Hi all,
The GeoServer team is pleased to announce the following releases:
These releases are shared to address a security vulnerability and is an urgent update for production systems:
-
CVE-2026-76904 PostGIS SQL Injection int the jsonArrayContains Function (Critical)
GeoServer is impaccted by a GeoTools CVE-2026-76904 SQL Injection vulnerability which affects PostGIS 12 and up. Unfortunately our coordinated vulnerability disclosure policy was not followed.
Each release is complete with docker image and windows installer. To find out more read the release announcements above.
Thanks to Andrea Aime (GeoSolutions) and Jody Garnett (GeoCat) for making these releases. We would also like to thank the hard work of geoserver-security team towards making these releases available promptly.
–
GeoServer Project Steering Committee