CVE-2023-25158
CVSS 9.8 CRITICAL: geoTools is an open source Java library that provides tools for geospatial data. EPSS 1% (63rd percentile).
Vulnerabilities · 41 days ago
CSIRT Italia said on August 18 that attackers are actively exploiting a GeoTools regression that brings back CVE-2023-25158 in live GeoServer stacks, and NCSC-NL said the vendor has issued fixes in GeoTools 35.1, 34.5, and 33.6. The issue affects the gt-jdbc-postgis component and the OGC filters GeoServer exposes through WFS and WMS endpoints.
The flaw is a pre-authentication SQL injection in the jsonArrayContains path: crafted requests can push unsanitized input into database queries against PostGIS-backed datastores. In some deployments, especially where the database runs with elevated rights, that SQL can spill past the database and become code execution on the server.
The lasting problem is that this is a regression, not a new bug, so fleets that believed they had already dealt with CVE-2023-25158 can become exposed again through downstream GeoTools builds. If GeoServer sits in front of privileged data stores, the blast radius now includes both database tampering and possible host compromise.
CVSS 9.8 CRITICAL: geoTools is an open source Java library that provides tools for geospatial data. EPSS 1% (63rd percentile).
5 sources covering this story
Rilevato sfruttamento di vulnerabilità in GeoServer
Rilevato lo sfruttamento attivo in rete di una vulnerabilità con gravità “critica” - già sanata dal vendor - relativa a GeoTools, libreria Java open source alla base delle funzionalità GIS di GeoServer.
ZeroDay Kwetsbaarheid verholpen in GeoTools door OpenGeo
GeoTools, een veelgebruikte open source Java-bibliotheek voor geospatiale data, heeft updates uitgebracht om ZeroDay SQL-injectie kwetsbaarheid te verhelpen in de uitvoering van OGC Filterfuncties bij gebruik met JDBCDataStore en andere datastores.
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
Unpatched GeoServer zero-day SQL injection is seeing active exploitation attempts hours after disclosure and can lead to remote code execution.
Attackers target zero-day vulnerability in geospatial data platform GeoServer
The unauthenticated SQL injection flaw could lead to remote code execution on certain server configurations.
Part of the PlainSec briefing for 2026-08-19