CVE-2026-76904
Last modified
CVE-2026-76904 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. Patches are available in versions 33.6, 34.5, and 33.6. No known workaround is available. To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| geotools | geotools | = 35.0; >= 34.0, < 34.5; >= 30.5, < 33.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-76904?
How severe is CVE-2026-76904?
How do I fix CVE-2026-76904?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76888RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …7.5
- CVE-2026-76889UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0…4.7
- CVE-2026-7689A security flaw has been discovered in Dolibarr ERP CRM up t…3.7
- CVE-2026-76890Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows…3.1
- CVE-2026-76891Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows…3.1
- CVE-2026-7690A weakness has been identified in Wavlink WL-WN570HA1 R70HA1…9.8
- CVE-2026-76905kin-openapi is a Go project for handling OpenAPI files. From…7.5
- CVE-2026-7691A security vulnerability has been detected in Wavlink WL-WN5…6.3
- CVE-2026-76917Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to…5.5
- CVE-2026-76918SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …5.5
- CVE-2026-76919ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …5.3
- CVE-2026-7692A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V…6.3
Are you affected by CVE-2026-76904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
