Vulnerabilities & Exploits · Web App Attack

GeoTools Regression Reopens GeoServer SQL Injection

CSIRT Italia said on August 18 that attackers are actively exploiting a GeoTools regression that brings back CVE-2023-25158 in live GeoServer stacks, and NCSC-NL said the vendor has issued fixes in GeoTools 35.1, 34.5, and 33.6. The issue affects the gt-jdbc-postgis component and the OGC filters GeoServer exposes through WFS and WMS endpoints.

The flaw is a pre-authentication SQL injection in the jsonArrayContains path: crafted requests can push unsanitized input into database queries against PostGIS-backed datastores. In some deployments, especially where the database runs with elevated rights, that SQL can spill past the database and become code execution on the server.

The lasting problem is that this is a regression, not a new bug, so fleets that believed they had already dealt with CVE-2023-25158 can become exposed again through downstream GeoTools builds. If GeoServer sits in front of privileged data stores, the blast radius now includes both database tampering and possible host compromise.

5 sources · Aug 18

CVE-2023-25158

NVD KEV

CVSS 9.8 CRITICAL: geoTools is an open source Java library that provides tools for geospatial data. EPSS 1% (63rd percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-08-17

Every edition of this story: GeoTools Regression Reopens GeoServer SQL Injection

More from today