# GeoServer zero-day vulnerability and response

> Live situation record from CLSTR: https://clstr.news/situations/geoserver-zero-day-vulnerability-and-response
> Updated: 2026-08-16T13:30:23.000Z. Sources: 4. Developments: 2.

A critical zero-day vulnerability was disclosed in the open-source geospatial platform GeoServer, specifically affecting the ‘jsonArrayContains’ functionality. This flaw allows for unauthorized SQL injection and, depending on system configurations, may enable remote code execution (RCE). Security firm WatchTowr reported observing hundreds of exploitation probes shortly after the vulnerability became public on August 12, 2026.

In response to the threat, GeoServer released an urgent maintenance update, version 2.28.5, to address the high-severity unauthenticated SQL injection vulnerability affecting PostGIS layers. Alongside this security patch, the developers released GeoServer 3.0-RC, a release candidate featuring a new user interface and support for newer deployment environments.

## Timeline

### 2026-08-16: GeoServer releases security update 2.28.5 and 3.0-RC

GeoServer has released maintenance version 2.28.5 to fix a high-severity SQL injection vulnerability and launched the 3.0-RC release candidate for public testing.

2 sources. https://clstr.news/cluster/geoserver-releases-security-update-2285-and-30-rc

### 2026-08-15: GeoServer zero-day vulnerability triggers mass exploitation probes

A critical zero-day vulnerability in GeoServer allows for SQL injection and potential remote code execution. Attackers began probing systems within hours of the flaw's public disclosure.

2 sources. https://clstr.news/cluster/geoserver-zero-day-vulnerability-triggers-mass-exploitation-probes

---
Cite as: GeoServer zero-day vulnerability and response. CLSTR, https://clstr.news/situations/geoserver-zero-day-vulnerability-and-response
