CVE-2026-108474 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-108474 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-108474 is a critical SQL injection vulnerability in JetBrains Exposed before 1.5.1. The flaw allows attacker-controlled string input to reach SQL functions without proper escaping, which can let an attacker read, modify, or delete database data depending on how the application uses Exposed. Even though there is no known exploitation in the wild and it is not in CISA KEV, the CVSS 9.8 rating means solo developers and small teams should treat this as an urgent patching issue.

If your service uses Exposed anywhere in its database layer, assume risk until you confirm you are on a fixed release and have tested the affected code paths.

Immediate Action

  • Upgrade JetBrains Exposed to 1.5.1 or later immediately. If you cannot patch today, isolate the service from untrusted input and restrict database permissions to the minimum required.
  • Search for direct use of SQL functions that accept strings from request data, query parameters, form fields, or message payloads. Treat any dynamic SQL as suspicious until reviewed.
  • Rollback only if the upgrade breaks production and you have a known-safe backup version. Do not roll back below 1.5.1 once you have confirmed exposure.
  • Temporarily disable or gate vulnerable endpoints that build SQL with user-controlled strings, especially admin tools, search features, filters, and reporting queries.
  • Review database credentials and permissions now. Use a low-privilege DB account so any injection has less blast radius.
  • Check the vendor advisory / release notes: JetBrains Exposed security advisory and JetBrains Exposed release notes.

Affected Versions

  • org.jetbrains.exposed:exposed-* before 1.5.1 vulnerable
  • 1.5.1 and later safe based on the published fix
  • If you use a BOM, platform, or dependency lockfile, verify the resolved Exposed version is 1.5.1+, not just the declared version

Resolution Guide

Java / Gradle

dependencies {
    implementation("org.jetbrains.exposed:exposed-core:1.5.1")
    implementation("org.jetbrains.exposed:exposed-dao:1.5.1")
    implementation("org.jetbrains.exposed:exposed-jdbc:1.5.1")
}

Java / Maven

<dependency>
  <groupId>org.jetbrains.exposed</groupId>
  <artifactId>exposed-jdbc</artifactId>
  <version>1.5.1</version>
</dependency>

JavaScript / npm, yarn, pnpm

Exposed is a Java/Kotlin library, so there is usually no npm/yarn/pnpm package to update. If your app is a mixed stack, patch the Java/Kotlin service that actually talks to the database.

Python / pip, pipx

Same note: this issue is in JetBrains Exposed, not a Python package. Update the JVM service or container image that includes Exposed.

Linux package managers

If Exposed is bundled in a distro package or internal app package, update the application package rather than the OS package:

sudo apt update
sudo apt install --only-upgrade TODO-your-app-package
# or
sudo yum update TODO-your-app-package

Docker image tags

docker pull TODO-your-image:1.5.1
docker stop TODO-container
docker rm TODO-container
docker run -d --name TODO-container TODO-your-image:1.5.1

Config hardening

# Example: restrict DB account privileges
# Use a read-only account for read paths, and a separate limited-write account for writes.
# Disable any debug/admin endpoint that accepts raw SQL or dynamic filters.
FEATURE_RAW_SQL=false
ADMIN_SQL_CONSOLE_DISABLED=true

Code fix example

Replace string concatenation or unsafe SQL function arguments with parameterized queries or typed expressions.

// Unsafe pattern: user input reaches SQL function as a raw string
val term = call.parameters["q"]!!
TransactionManager.current().exec(
    "SELECT * FROM users WHERE lower(name) = lower('$term')"
)

// Safer pattern: parameterize the value
Users.select { Users.name.lowerCase() eq term.lowercase() }

Detection & Verification

Check your version

./gradlew dependencies | grep -i exposed
mvn dependency:tree | grep -i exposed

Look for vulnerable patterns

grep -RIn --exclude-dir=build --exclude-dir=.gradle \
  -E "exec\(|rawSql|lowerCase\(|upperCase\(|substring\(|trim\(|replace\(" .

Dependency audit

./gradlew dependencyInsight --dependency exposed --configuration runtimeClasspath
mvn -q dependency:tree -Dincludes=org.jetbrains.exposed

Verify the fix

# Confirm the resolved runtime version is 1.5.1 or newer
./gradlew dependencies | grep -i "org.jetbrains.exposed"

# Re-run tests that cover request-driven search/filter endpoints
./gradlew test

# If you have a staging DB, confirm no raw SQL is built from user input
grep -RIn "TODO: unsafe sql" src test

Risk and Impact

This bug can let a remote attacker inject SQL through unescaped string arguments passed to certain Exposed SQL functions. In practical terms, that may expose customer data, alter records, bypass authorization checks, or destroy tables if the database account has broad permissions.

The blast radius depends on how Exposed is used and how much database access the application account has. Small teams are especially at risk because one vulnerable endpoint can affect the entire database, backups, and downstream services that trust the same data.

Keep reading