GeoTools released version 35.1 with a security fix for GHSA-mqjf-5f49-2fjh / CVE-2026-76904, an unauthenticated SQL injection issue affecting the PostGIS layer's jsonArrayContains filter handling. The flaw was tied to SQL generation in FilterToSqlHelper, a code path used to build PostGIS jsonb_path_exists expressions, and was disclosed alongside another advisory involving SchemaCache.resolveLocation writing outside the cache directory.
A related GeoTools commit updated FilterToSqlHelper.java to escape JSON literal values before inserting them into generated SQL and expanded tests in PostgisJsonPathExistsTest.java to verify correct handling of apostrophes in property names and values. Project activity also shows the affected area had recently been modified for PostgreSQL JSON array search behavior, and the fix was merged to the main branch with backport attempts for the 33.x, 34.x, and 35.x lines, indicating maintainers are addressing exposure across supported releases.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
GeoTools 35.1 release notes listed security issue GEOT-7959, mapped to GHSA-mqjf-5f49-2fjh, describing a PostGIS SQL injection vulnerability via the jsonArrayContains function. The same release also included another security advisory, GHSA-cvw8-9fcf-4wxj, for SchemaCache.resolveLocation.
After the merge, an automatic cherry-pick of commit ed4fe9e5b8730608d8dee97abf5d43b4c38dc047 failed for branch 33.x with a content conflict in FilterToSqlHelper.java. The repository bot labeled the backport as failed and suggested a manual cherry-pick workflow.
Pull request #5829 for GEOT-7958 was merged into the geotools main branch as commit d821c4d, with 30 of 32 checks passing. The PR concerned increased FilterToSqlHelper test coverage in the code area later referenced as security-relevant.
A GeoTools commit updated FilterToSqlHelper.java so string values are passed through escapeJsonLiteral before being inserted into generated jsonb_path_exists expressions. The same commit expanded PostGIS tests to verify apostrophe escaping in jsonArrayContains SQL generation.
GeoTools tracked GEOT-7589 to fix JsonArrayDelegation for Postgres so searches would support root-level arrays. This establishes earlier development work in the same PostGIS jsonArrayContains area later tied to the vulnerability.
An Argus AI Threat Intelligence mention identified CVE-2026-76904 as an unauthenticated SQL injection in GeoTools' PostGIS-layer jsonArrayContains filter function. This tied the vulnerable behavior to a CVE identifier and described the issue's impact.
Craigds referenced the pull request in koordinates/geotools#1 under the title 'Escape json literal in jsonb_path_exists encoding.' This publicly connected the change to escaping behavior in GeoTools' PostGIS JSON-path SQL generation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceosgeo-org.atlassian.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.