Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 4 sources · 2 days · First seen · Last updated
GeoServer zero-day vulnerability and response
Overview
A critical zero-day vulnerability was disclosed in the open-source geospatial platform GeoServer, specifically affecting the ‘jsonArrayContains’ functionality. This flaw allows for unauthorized SQL injection and, depending on system configurations, may enable remote code execution (RCE). Security firm WatchTowr reported observing hundreds of exploitation probes shortly after the vulnerability became public on August 12, 2026.
In response to the threat, GeoServer released an urgent maintenance update, version 2.28.5, to address the high-severity unauthenticated SQL injection vulnerability affecting PostGIS layers. Alongside this security patch, the developers released GeoServer 3.0-RC, a release candidate featuring a new user interface and support for newer deployment environments.
Entities
Timeline
-
26 days ago
[TECHNOLOGY] 2 sourcesGeoServer releases security update 2.28.5 and 3.0-RCGeoServer has released maintenance version 2.28.5 to fix a high-severity SQL injection vulnerability and launched the 3.0-RC release candidate for public testing.
-
28 days ago
[TECHNOLOGY] 2 sourcesGeoServer zero-day vulnerability triggers mass exploitation probesA critical zero-day vulnerability in GeoServer allows for SQL injection and potential remote code execution. Attackers began probing systems within hours of the flaw's public disclosure.
Sources
dev.to · geoserver.org · kronan.se · securityaffairs.co