< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 2 days · First seen · Last updated

GeoServer zero-day vulnerability and response

Overview

A critical zero-day vulnerability was disclosed in the open-source geospatial platform GeoServer, specifically affecting the ‘jsonArrayContains’ functionality. This flaw allows for unauthorized SQL injection and, depending on system configurations, may enable remote code execution (RCE). Security firm WatchTowr reported observing hundreds of exploitation probes shortly after the vulnerability became public on August 12, 2026.

In response to the threat, GeoServer released an urgent maintenance update, version 2.28.5, to address the high-severity unauthenticated SQL injection vulnerability affecting PostGIS layers. Alongside this security patch, the developers released GeoServer 3.0-RC, a release candidate featuring a new user interface and support for newer deployment environments.

Entities

GeoServer · GeoTools · WatchTowr · OSGeo · CISA

Timeline

  1. 26 days ago

    [TECHNOLOGY] 2 sources
    GeoServer releases security update 2.28.5 and 3.0-RC

    GeoServer has released maintenance version 2.28.5 to fix a high-severity SQL injection vulnerability and launched the 3.0-RC release candidate for public testing.

  2. 28 days ago

    [TECHNOLOGY] 2 sources
    GeoServer zero-day vulnerability triggers mass exploitation probes

    A critical zero-day vulnerability in GeoServer allows for SQL injection and potential remote code execution. Attackers began probing systems within hours of the flaw's public disclosure.

Sources

dev.to · geoserver.org · kronan.se · securityaffairs.co