Critical SQL Injection Vulnerability in GeoPandas Affects Multiple Ubuntu Releases

Critical SQL Injection Vulnerability in GeoPandas Affects Multiple Ubuntu Releases

First seen 11 Mar 2026, 15:25 UTC UbuntuLinuxsecurity 57.8

Article Content

Browse articles
ThreatCluster

A significant SQL injection vulnerability has been identified in GeoPandas, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The vulnerability, cataloged as CVE-2025-69662, was published on January 30, 2026. It was discovered that GeoPandas improperly handled certain input, allowing potential attackers to exploit this flaw for SQL injection attacks. Users of the affected Ubuntu releases are urged to update to the patched versions of python3-geopandas to mitigate the risk. The recommended package versions include python3-geopandas 1.0.1-2ubuntu0.1 for Ubuntu 25.10, 0.14.3-2ubuntu0.1 for 24.04 LTS, and 0.10.2-1ubuntu0.1 for 22.04 LTS. A standard system update will apply the necessary changes to address this vulnerability. The issue poses a medium-level threat due to its potential for exploitation if left unpatched.

Key Points: • GeoPandas has a critical SQL injection vulnerability affecting multiple Ubuntu versions. • Users are advised to update to specific patched versions of python3-geopandas. • The vulnerability is cataloged as CVE-2025-69662, published on January 30, 2026.

Timeline

2026-01-30
CVE-2025-69662 published
2026-03-11
Ubuntu releases patch for GeoPandas vulnerability