A critical vulnerability (CVE-2023-25158) in GeoServer allows unauthenticated SQL injection attacks via the jsonArrayContains filter function, which poses a high risk due to its CVSS score of 9.8. This flaw affects various versions of GeoServer with PostGIS, potentially leading to remote code execution (RCE) if exploited with sufficient database privileges. Active exploitation attempts have been noted since the flaw's public disclosure, with over 1,500 exposed instances reported.
It's essential to update to patched versions (28.2, 27.4, and 26.7) and limit public access to GeoServer until fixes are applied. A detailed technical analysis and proof-of-concept exploit code are available for reference.