Articles

GeoServer Zero-Day (CVSS 9.8): SQL Injection to RCE

An unpatched GeoServer SQL injection zero-day rated CVSS 9.8 is under active exploitation. The flaw, affected versions, the fix, and what to do now.

Chisato Chisato · · 5 min read
An open padlock resting on a laptop keyboard, representing an exploited software vulnerability

A critical SQL injection flaw in GeoServer, the widely deployed open-source geospatial data server, is being probed in the wild within hours of its public disclosure — and under the right database configuration it leads all the way to remote code execution. Tracked under GitHub advisory GHSA-mqjf-5f49-2fjh and rated CVSS 9.8, the vulnerability was disclosed on August 12, 2026, and threat-intelligence teams began observing exploitation attempts almost immediately, before many operators had a chance to patch.

The severity rating is not incidental. A CVSS 9.8 is reserved for flaws that are network-reachable, require little or no privilege, and carry a high impact to confidentiality, integrity, and availability. This one qualifies: an unauthenticated attacker who can reach a vulnerable instance can inject arbitrary SQL, and against a sufficiently privileged database account that injection becomes a path to running commands on the server.

The vulnerability

The bug lives in the jsonArrayContains filter function, used with GeoServer’s PostGIS data-store implementation. That function — jsonArrayContains(<column>, <pointer>, <value>) — is meant to query JSON array fields and check whether they contain a given value. The problem is that on PostGIS 12 and greater, the supplied <value> argument is written into the generated SQL without escaping, so an attacker can break out of the intended query and inject their own SQL. Our primer on SQL injection covers exactly this class of flaw: untrusted input concatenated into a query instead of being safely parameterized.

Because the vulnerable filter can be reached through GeoServer’s standard OGC filter interfaces — the query mechanisms the platform exposes to serve map and feature data — the injection requires no authentication. An attacker needs only network access to a vulnerable endpoint. Where the injection escalates to remote code execution is when the underlying database connects with a high-privilege account: on a PostgreSQL system administrator (sa-class) connection, SQL injection can be leveraged to execute operating-system commands, turning a data-query flaw into full server compromise.

Notably, the advisory identifies this as a regression of CVE-2023-25158, an earlier critical GeoServer SQL injection that was patched back in February 2023. A code path that was believed fixed reintroduced the same underlying weakness — a reminder that regressions of known-critical bugs are among the most reliable places for attackers to look. This echoes the pattern in other recently exploited open-source flaws, like the Langflow RCE that turned an AI-workflow tool into a foothold.

Active exploitation

What makes this a genuine emergency rather than a routine patch item is the timeline. The flaw was disclosed publicly — reportedly first surfaced by a researcher on X — and exploitation attempts were detected within hours. Security teams tracking the activity have reported hundreds of attempts originating from a small pool of IP addresses, the signature of opportunistic scanning against a freshly disclosed, high-value target.

The compressed window between disclosure and exploitation is the whole story here. This is effectively a zero-day scenario for any operator who had not patched by the time the details went public: attackers had a working understanding of the bug at the same moment defenders did. For background on why that gap is so dangerous, see our explainer on zero-day vulnerabilities.

Who is exposed

GeoServer is one of the most widely used open-source platforms for publishing and sharing geospatial data. It underpins mapping and location services across government agencies, utilities, transportation and logistics operators, environmental and land-management bodies, and countless private-sector GIS deployments. Many of these instances are internet-facing by design, because their job is to serve map layers and feature data to browsers and downstream applications.

The specific precondition — the PostGIS data store with a String or JSON field on PostGIS 12+ — narrows the population of exploitable instances, but not dramatically: PostGIS is the default spatial database pairing for GeoServer, and the affected versions span current release lines. Any organization running an exposed GeoServer against a modern PostGIS backend should treat itself as in scope until proven otherwise.

The fix and mitigations

The GeoServer project has shipped patched releases: 3.0.1, 2.28.5, and 2.27.6. Upgrading to one of these is the definitive remedy, and given active exploitation, it is urgent rather than routine.

Operators who cannot patch immediately face a harder problem than usual: the advisory states that no complete mitigation is available short of the fix. Critically, the workaround that addressed the earlier CVE-2023-25158 — enabling prepared statements and disabling the encode functions — is not effective against this variant. That leaves defenders relying on exposure reduction rather than a clean configuration toggle:

  • Restrict network access. Put the GeoServer instance behind network-level controls so untrusted clients cannot reach the OGC filter endpoints. A web application firewall tuned to flag suspicious filter payloads can add a layer, though it is not a substitute for patching.
  • Limit the vulnerable function. Where feasible, disable or restrict use of the jsonArrayContains function until the upgrade is applied.
  • Reduce database privileges. The jump from SQL injection to RCE depends on an over-privileged database connection. Running GeoServer against a least-privilege PostGIS account — no system-administrator rights, no unnecessary function access — blunts the worst-case outcome even if injection succeeds.
  • Hunt for signs of exploitation. Review logs for anomalous OGC filter requests referencing jsonArrayContains, unexpected database errors, and outbound connections from the GeoServer host.

What it means

The GeoServer zero-day is a textbook case of the modern patch race, and three things make it worth attention beyond the immediate fire drill.

The regression is the lesson. This is the same fundamental bug as a 2023 critical that was supposedly closed. Reintroduced weaknesses are a recurring failure mode in large codebases, and they reward attackers who keep old exploit knowledge on file. For defenders, it argues for regression testing around previously patched security flaws — not just forward-looking review.

Exposure, not just patch status, decides who gets hit. Because there is no reliable configuration-only mitigation, organizations that treated an internet-facing GeoServer as low-risk infrastructure are now exposed to unauthenticated RCE. The instances most at risk are exactly the ones that have been running quietly for years — public map servers nobody thinks of as an attack surface. The parallel to recent maximum-severity flaws like the Metabase zero-day is direct: a back-office data tool becomes the front door.

What to watch next: whether a CVE identifier is formally assigned (the flaw was tracked by GitHub advisory ahead of a CVE), whether exploitation broadens from opportunistic scanning to targeted intrusions, and whether CISA adds it to the Known Exploited Vulnerabilities catalog — which would put a hard remediation deadline on U.S. federal operators. For anyone running GeoServer on PostGIS, the action item is not conditional: patch to 3.0.1, 2.28.5, or 2.27.6 now, and assume exposed instances may already have been probed.

Chisato Chisato · · 6 min read

Chrome Zero-Day CVE-2026-85046: V8 Flaw Exploited

Google patched CVE-2026-85046, an actively exploited V8 type-confusion zero-day in Chrome and the sixth of 2026. Affected versions, the risk, and how to patch.

#Security #Zero-Day #Chrome
Chisato Chisato · · 5 min read

PaperCut NG/MF Zero-Day: Patch All Versions Now

PaperCut is patching two zero-days in NG and MF — a pre-auth RCE and an access-control flaw — exploited in the wild. All versions affected. Apply Release 2.

#Security #Cybersecurity #Zero-Day