# GeoServer releases fix for SQL injection flaw after reported scans

_Published Sunday, August 16, 2026 at 7:31 AM EDT · Security · Latest · Tier 2 — Notable_

![GeoServer releases fix for SQL injection flaw after reported scans — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBHrFMdn5ekgZuyeE4m-ez0biA_lSQ3abNCs7s0YNhWXi-MvjTNhJBgQtjTw_j9zNfDNtp0DtDC6wH9lJcD7obhh9ujkfuk6E0FiX9qH3njE5mcNrtyaxWR3E2RO1ROmlx4B4YbjBtby_P9FXXpl-Be9voGWxC7PbkyVpBrk1zB3KanenH2jVRf_Uv48s4/s1700-e365/geo.jpg)

GeoServer released versions 3.0.1, 2.28.5 and 2.27.6 to address an SQL injection vulnerability in the PostGIS DataStore implementation, according to The Hacker News. The report says watchTowr observed hundreds of exploitation attempts from a small pool of IP addresses after public disclosure. Project maintainers said the flaw affects the jsonArrayContains function, which can write a value into generated SQL without escaping in affected PostGIS configurations. The vulnerability has GitHub advisory identifier GHSA-mqjf-5f49-2fjh and a reported CVSS score of 9.8.

## Sources

- [thehackernews.com](https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html)

---
Canonical: https://techandbusiness.org/newswire/PvW1j7EwKMIVTk-gEmnpuR
Published: 2026-08-16T11:31:54.237Z
Story chronology: 2026-08-13T18:45:00.000Z
Retrieved: 2026-09-30T16:35:33.095Z
Publisher: Tech & Business (techandbusiness.org)
