GeoServer Zero-Day Is Already Being Probed. That’s the Problem
Brief
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.
A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure.
A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier.
实话说今天是非常不开心的一天 实际上最近一段时间我都非常沮丧 各种事情 所以我公布一个0day 希望让你们心情变的开心
GeoServer jsonArrayContains 未授权 SQL 注入 数据库sa的情况下理所当然的可以rce pic. twitter. com/0uTUyMNYU4
— 秋风 (@q1uf3ng) August 12, 2026
The flaw lies in the jsonArrayContains functionality and allows unauthorised SQL injection.
