GeoTools/GeoServer OGC filter SQL injection fixed in 2023. Referenced by the 2026-08-18 GeoServer entry as the flaw the jsonArrayContains injection regresses: GeoTools states the mitigation published for this CVE (enabling prepared statements and disabling encode functions) is not effective against the 2026 variant, so operators who applied it are not protected.
cve · CVE-2023-25158
Coverage timeline
0
first 2026-08-18 → last 2026-08-18
no data
Peak priority
·
no matching entries
Sources cited
0
0 hosts
Sections touched
0
·
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
Story timeline
No published entries reference this entity yet.
Entries about GeoTools/GeoServer OGC filter SQL injection fixed in 2023. Referenced by the 2026-08-18 GeoServer entry as the flaw the jsonArrayContains injection regresses: GeoTools states the mitigation published for this CVE (enabling prepared statements and disabling encode functions) is not effective against the 2026 variant, so operators who applied it are not protected.
No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.