CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2023-25158

unknowncovered by 1 sourcefirst seen 2026-08-18
GeoTools, a widely-used open source Java library for geospatial data, has released updates to fix a ZeroDay SQL injection vulnerability in the execution of OGC Filter functions when used with JDBCDataStore and other datastores. The mentioned vulnerability is a legacy vulnerability that has recently been found to not have been adequately fixed. The vulnerability allowed a malicious actor to execute arbitrary SQL code in the underlying database. The ZeroDay vulnerability is present in multiple OGC Filter functions that enable SQL injection when used with various datastore implementations such as PostGIS. This allows an attacker to inject malicious SQL code through these functions. The vulnerabilities are present in multiple versions of GeoTools. As partial mitigation, encode functions can be disabled and prepared statements can be enabled to reduce exposure. If the underlying database is running with elevated privileges, it is possible to execute arbitrary code on the server through this vulnerability, which could result in both unauthorized database manipulation and a potential system takeover. Researchers have received reports that malicious actors have drawn attention to the new ZeroDay and are observing an increase in scan and exploit traffic. At this time, there is no evidence of large-scale unauthorized access or actual abuse. For this new ZeroDay vulnerability, (yet) no CVE ID has been assigned.

CSIRTS triage

What
SQL injection vulnerability in OGC Filter functions allows arbitrary SQL code execution in the underlying database when used with JDBCDataStore and other datastores.
Who is affected
Deployments using GeoTools with OGC Filter functions and JDBC or PostGIS datastores are affected.
Urgency
High urgency; this is a legacy vulnerability recently found inadequately fixed that enables direct database compromise.
Action
Update GeoTools to the patched version; as interim mitigation, disable encode functions and enable prepared statements.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2023-25158

Get an email if CVE-2023-25158 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2023-25158

CVE.org record

Embed the live status

CVE-2023-25158 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2023-25158 status](https://www.csirts.com/badge/CVE-2023-25158)](https://www.csirts.com/cve/CVE-2023-25158)