# GeoServer releases fix for SQL injection flaw after reported scans

_Thursday, August 13, 2026 at 2:45 PM EDT · Security · Latest · Tier 2 — Notable_

![GeoServer releases fix for SQL injection flaw after reported scans — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBHrFMdn5ekgZuyeE4m-ez0biA_lSQ3abNCs7s0YNhWXi-MvjTNhJBgQtjTw_j9zNfDNtp0DtDC6wH9lJcD7obhh9ujkfuk6E0FiX9qH3njE5mcNrtyaxWR3E2RO1ROmlx4B4YbjBtby_P9FXXpl-Be9voGWxC7PbkyVpBrk1zB3KanenH2jVRf_Uv48s4/s1700-e365/geo.jpg)

GeoServer released versions 3.0.1, 2.28.5 and 2.27.6 to address an SQL injection vulnerability in the PostGIS DataStore implementation, according to The Hacker News. The report says watchTowr observed hundreds of exploitation attempts from a small pool of IP addresses after public disclosure. Project maintainers said the flaw affects the jsonArrayContains function, which can write a value into generated SQL without escaping in affected PostGIS configurations. The vulnerability has GitHub advisory identifier GHSA-mqjf-5f49-2fjh and a reported CVSS score of 9.8.

## Sources

- [thehackernews.com](https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html)

---
Canonical: https://techandbusiness.org/newswire/PvW1j7EwKMIVTk-gEmnpuR
Retrieved: 2026-08-16T14:27:59.037Z
Publisher: Tech & Business (techandbusiness.org)
