VDB

GCVE-110-NCSC-2026-304

GCVE-110-NCSC-2026-304
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published August 18, 2026
GeoTools, an open source Java library for geospatial data, contains SQL Injection vulnerabilities in OGC Filter executions with JDBCDataStore, affecting multiple versions and datastores, with patches available from versions 24.7 to 28.2.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
GeoToolsvers:unknown/*

References

advisory
advisory
advisory

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›