External risk intelligence

GeoTools SQL Injection Vulnerability in PostGIS DataStore filters.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-76904

GeoTools is a library embedded within applications to process geospatial data. While it can be used in internet-facing web services or APIs that expose OGC filters to end-users, it is also frequently used in internal GIS tools, data processing pipelines, or desktop applications where it is not directly reachable from the public internet.

SQL Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in the GeoTools open-source Java library, which is used for processing geospatial data. The issue, an SQL Injection vulnerability, arises when specific functions are used with PostGIS data. If exploited, this could allow unauthorized parties to manipulate or access data. The primary concern is to confirm if this library is in use and if the affected functions are being utilized, particularly in internet-facing applications.

  • Text vulnerability allows data manipulation.
  • Understand if GeoTools is in use.
  • Confirm relevance and exposure to critical risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted OGC filters to an application that uses the affected GeoTools library with the PostGIS DataStore. This could lead to attackers executing arbitrary SQL commands.

  • No authentication or privileges required.
  • Malicious OGC filter via `jsonArrayContains`.
  • Complete database compromise possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to inject malicious SQL commands when processing geospatial data through the PostGIS DataStore implementation, specifically when using the `jsonArrayContains` function with a string or JSON field and PostGIS 12 or greater. This could lead to unauthorized data access or modification within the geospatial database.

  • Geospatial data in PostGIS databases.
  • Via unescaped user input in `jsonArrayContains` calls.
  • Unauthorized access or modification of data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The GeoTools library, used for geospatial data processing, is susceptible to an SQL Injection vulnerability when interacting with PostGIS. Application owners and platform teams are likely responsible for managing instances of GeoTools. The immediate priority is to identify all deployments, confirm their exposure and criticality, and then plan remediation, prioritizing those systems with the greatest risk.

  • Application owners should own the issue.
  • Verify PostGIS interaction and data sensitivity.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GeoTools?

GeoTools is an open-source Java library developers use to build applications that process, analyze, and render geospatial data. It provides the building blocks for spatial data infrastructure, often serving as the engine behind GIS tools, mapping software, and web services that handle complex map-based data stored in databases like PostGIS.

What is the vulnerability in CVE-2026-76904?

This is an SQL Injection (CWE-89) vulnerability. It occurs because the library fails to properly sanitize user-provided input before including it in a database query. Specifically, when the 'jsonArrayContains' function processes filters, it embeds the value directly into the generated SQL, potentially allowing an unauthorized party to execute arbitrary commands against the connected database.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted OGC filter to an application that utilizes the affected GeoTools version. The flaw only exists when using the PostGIS DataStore with PostGIS version 12 or greater, specifically when targeting a string or JSON field. If your application logic does not use the 'jsonArrayContains' function, or if it uses an older version of PostGIS, the specific flaw described cannot be triggered.

Why should I care about this if my app is internal?

Halo Surface Signal notes that while GeoTools is often used in internal GIS tools or data pipelines, it is frequently embedded in internet-facing web services. If your application exposes OGC filters to end-users or the public internet, the risk is higher as it is directly reachable. Regardless of location, if an internal user or automated system can supply malicious filter input, the integrity of the underlying database remains at risk.

How do I fix CVE-2026-76904?

The primary fix is to update the GeoTools library to a patched version, such as 33.6, 34.5, or 35.1. Since there is no known workaround, you must identify all software deployments using the affected library versions. As a temporary defensive measure to limit potential impact while planning your updates, ensure your database connection pool is configured with the minimum necessary permissions to perform its required tasks.

References