PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76904 GeoTools CVE debrief

CVE-2026-76904 is a critical SQL injection vulnerability in GeoTools, a Java library for geospatial data, versions 30.5 and prior to 33.6, 34.5. The vulnerability is present when executing OGC Filters with PostGIS DataStore implementation using the `jsonArrayContains` function. This function writes user input into generated SQL without escaping, allowing attackers to inject malicious SQL code. The vulnerability has a CVSS score of 9.8 and is considered critical. Patches are available in versions 33.6, 34.5, and 33.6. GeoTools users should prioritize patching to prevent potential SQL injection attacks. The PostGIS connection pool should be configured with limited rights to reduce the attack surface. Evidence is based on official CVE and NVD records, as well as GitHub references. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. They should also review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.

Vendor
GeoTools
Product
GeoTools
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

GeoTools users, administrators, and developers who use PostGIS with GeoTools should be aware of this vulnerability and take action to patch or mitigate it. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platforms, and security teams should also be aware of the potential impact on their systems and take necessary actions to protect them. Vulnerability management and security teams should prioritize patching and verify affected product deployments. Asset owners should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should also monitor for suspicious SQL queries and exception tracking. This may involve reviewing system logs, network traffic, and other relevant data to detect potential attacks. By taking these steps, GeoTools users can help prevent potential SQL injection attacks and protect their systems from exploitation. This requires coordination between development, operations, and security teams to ensure that patches are applied, compensating controls are in place, and systems are monitored for potential attacks. Effective communication and incident response planning are also essential to minimize the impact of a potential attack. By prioritizing patching and taking proactive steps to protect their systems, GeoTools users can reduce the risk of a successful attack and protect their data and assets. This vulnerability highlights the importance of secure coding practices, regular security testing, and timely patching of vulnerabilities to prevent potential attacks. By staying informed and taking proactive steps, GeoTools users can help protect their systems and data from潜在的

Technical summary

CVE-2026-76904 is a critical SQL injection vulnerability in GeoTools, a Java library for geospatial data, versions 30.5 and prior to 33.6, 34.5. The vulnerability is present when executing OGC Filters with PostGIS DataStore implementation using the `jsonArrayContains` function. Patches are available in versions 33.6, 34.5, and 33.6. GeoTools users should prioritize patching to prevent potential SQL injection attacks. The PostGIS connection pool should be configured with limited rights to reduce the attack surface.

Defensive priority

GeoTools users should prioritize patching to prevent potential SQL injection attacks.

Recommended defensive actions

  • Apply patches in versions 33.6, 34.5, or 33.6 to fix the SQL injection vulnerability.
  • Configure the PostGIS connection pool with limited rights to reduce the attack surface.
  • Inventory checks: Verify GeoTools version and PostGIS configuration.
  • Monitor for suspicious SQL queries and exception tracking.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE-2026-76904 record indicates a critical SQL injection vulnerability in GeoTools, a Java library for geospatial data, versions 30.5 and prior to 33.6, 34.5. Patches are available in versions 33.6, 34.5, and 33.6. Evidence is based on official CVE and NVD records, as well as GitHub references. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. They should also review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:06.143Z and has not been modified since then.