CVE-2026-76904 is an unauthenticated SQL-injection vulnerability in GeoTools' gt-jdbc-postgis PostGIS DataStore implementation. When processing OGC filters using the jsonArrayContains function against PostGIS 12 or later, the implementation incorporates the attacker-controlled value argument into a generated SQL/JSON path expression without adequate escaping. Crafted filter values can therefore alter the intended database query. Affected releases are GeoTools 30.5 through 33.5, 34.0 through 34.4, and 35.0. The issue is fixed in 33.6, 34.5, and 35.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains two Python 3 scripts and a German README. It is not a Metasploit, Nuclei, or other established exploit-framework module. geoserver_sqli_working.py is the active exploit entry point for the claimed GeoServer JSONPath injection CVE-2026-76904. It disables TLS certificate verification, sends WFS 2.0 GetFeature requests with resultType=hits, and places an encoded CQL_FILTER payload in the query string. Its payload targets PostgreSQL semantics: unconditional pg_sleep establishes injection, while four conditional pg_sleep constructions are tested to find a usable boolean timing oracle. A successful oracle supports blind extraction of arbitrary supplied SQL query output, with built-in queries focused on PostgreSQL server and catalog reconnaissance. wfs_inventory.py is a substantially larger companion inventory/export tool. It uses standard WFS GetCapabilities, DescribeFeatureType, and GetFeature operations to stream layer names, parse XSD field definitions, identify likely candidate properties, sample/export values, and optionally conduct the same pg_sleep-based timing confirmation against discovered fields. It supports auto, layers, fields, and values modes; output/report formats; paging; namespace/layer limits; candidate scopes; diagnostic output; and capability-file parsing. Although described as read-only for normal operation, enabling --sleep sends an injection-bearing CQL_FILTER and is therefore an active vulnerability-verification mode. No fixed victim domain, IP address, DNS name, or credentials are embedded. Targets, layer names, fields, and optional SQL queries are supplied by the operator. A default type name (fink_bku:fink_meta_mitte_suedwest) is present in the PoC argument parser, but exploitation still requires a target URL and a valid field name.
This repository is a small standalone Python proof-of-concept exploit for an unauthenticated GeoServer/GeoTools SQL injection that is claimed to lead to RCE through PostgreSQL COPY TO PROGRAM. The repository contains four files: a README with vulnerability background, exploitation examples, and lab instructions; a docker-compose.yml that provisions a GeoServer plus PostGIS/PostgreSQL test environment; a .gitignore; and the main exploit script exploit.py. The exploit logic is entirely in exploit.py. The build_payload() function takes a target column and operator-supplied OS command, escapes single quotes for SQL, wraps the command in COPY (SELECT 1) TO PROGRAM '<command>', then embeds that SQL into a malicious CQL_FILTER value. The injected filter is designed to terminate the intended jsonArrayContains expression and append arbitrary SQL. The exploit_rce() function sends an HTTP GET request with WFS parameters (service=WFS, version=2.0.0, request=GetFeature, typeNames=<workspace>:<layer>, outputFormat=application/json, and the malicious CQL_FILTER) to the constructed endpoint <base_url>/<workspace>/ows. It treats HTTP 200, 400, or 500 as possible success indicators, with 400 explicitly noted as an expected injection signal. Operationally, this is an RCE enabler rather than a post-exploitation framework: the operator supplies the exact command to run, such as creating a file or launching a reverse shell. There is no automated callback handling, shell staging, persistence, or target discovery. The included docker-compose lab shows the intended target profile: GeoServer connected to PostgreSQL/PostGIS, with example REST API calls to create a datastore and publish a layer. Overall, the repository’s purpose is to demonstrate and validate SQL injection to command execution against a vulnerable GeoServer deployment backed by PostgreSQL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A critical SQL injection vulnerability in GeoTools' org.geotools.jdbc:gt-jdbc-postgis PostGIS DataStore implementation. The jsonArrayContains function can insert an unescaped value into generated SQL when used with PostGIS 12 or later.
A critical unauthenticated SQL injection vulnerability in GeoTools' PostGIS DataStore implementation, where the `jsonArrayContains` function writes attacker-controlled `<value>` into generated SQL without escaping.
A critical unauthenticated SQL injection vulnerability in the GeoTools gt-jdbc-postgis/PostGIS DataStore component, specifically the jsonArrayContains OGC filter handling, which can allow arbitrary SQL execution and potentially remote code execution on the backend database server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.