CVE-2023-25158
CVSS 9.8 CRITICAL: geoTools is an open source Java library that provides tools for geospatial data. EPSS 1% (63rd percentile).
Vulnerabilities & Exploits · Web App Attack
CSIRT Italia said on August 18 that attackers are actively exploiting a GeoTools regression that brings back CVE-2023-25158 in live GeoServer stacks, and NCSC-NL said the vendor has issued fixes in GeoTools 35.1, 34.5, and 33.6. The issue affects the gt-jdbc-postgis component and the OGC filters GeoServer exposes through WFS and WMS endpoints.
The flaw is a pre-authentication SQL injection in the jsonArrayContains path: crafted requests can push unsanitized input into database queries against PostGIS-backed datastores. In some deployments, especially where the database runs with elevated rights, that SQL can spill past the database and become code execution on the server.
The lasting problem is that this is a regression, not a new bug, so fleets that believed they had already dealt with CVE-2023-25158 can become exposed again through downstream GeoTools builds. If GeoServer sits in front of privileged data stores, the blast radius now includes both database tampering and possible host compromise.
5 sources · Aug 18
CVSS 9.8 CRITICAL: geoTools is an open source Java library that provides tools for geospatial data. EPSS 1% (63rd percentile).
CSIRT Italia / ACN
Rilevato sfruttamento di vulnerabilità in GeoServer
Rilevato lo sfruttamento attivo in rete di una vulnerabilità con gravità “critica” - già sanata dal vendor - relativa a GeoTools, libreria Java open source alla base delle funzionalità GIS di GeoServer.
originalNCSC-NL Advisories
ZeroDay Kwetsbaarheid verholpen in GeoTools door OpenGeo
GeoTools, een veelgebruikte open source Java-bibliotheek voor geospatiale data, heeft updates uitgebracht om ZeroDay SQL-injectie kwetsbaarheid te verhelpen in de uitvoering van OGC Filterfuncties bij gebruik met JDBCDataStore en andere datastores.
originalSecurityWeek
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
originalPart of the PlainSec briefing for 2026-08-15
Every edition of this story: GeoTools Regression Reopens GeoServer SQL Injection