{
  "id": 952362,
  "title": "GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration",
  "url": "https://urgent.news/2026/08/15/geoserver-jsonarraycontains-sql-injection-zero-day-mass-probes-hours",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-15T04:22:49.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/geoserver-jsonarraycontains-sql-injection-zero-day-mass-probes-hours-after-disclosure-rce-159a"
  },
  "original_language": "en",
  "account": "A critical SQL injection vulnerability was discovered in GeoServer's jsonArrayContains filter. Within hours of its public disclosure, hundreds of unauthorized attempts were made to exploit this flaw. The GeoServer jsonArrayContains function improperly includes user-provided arguments in database queries, allowing attackers to manipulate data and potentially execute arbitrary code depending on the server's configuration. While no confirmed remote code execution (RCE) cases have been reported, the vulnerability is particularly dangerous for systems running GeoServer with PostGIS, Oracle, or H2 data stores and without proper security measures. Organizations should immediately apply patches, limit exposure, and monitor for abnormal filter queries, SQL errors, and child processes indicating potential attacks.",
  "summary": "GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration 1. Basic Information Severity: Critical Article Title: Hackers Exploiting Unpatched GeoServer Zero-Day Publisher: SecurityWeek Publication Date: 2026-08-14 Update Date: None Original Article: Original Article Related Sources: None Malware: None Groups: None CVEs:…",
  "key_points": [
    "Critical SQL injection flaw found in GeoServer jsonArrayContains filter.",
    "Hundreds of unauthorized attempts made hours after disclosure.",
    "RCE possible depending on server configuration and data store."
  ],
  "editors_take": "This vulnerability allows attackers to manipulate data and potentially execute arbitrary code, posing a significant threat to systems with specific configurations and inadequate security measures.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}