CVE-2026-42030: MapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in OpenLayers viewer
MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary HTML/JavaScript into the browser of any user who opens a crafted WMS URL. The vulnerability is triggered via FORMAT=application/openlayers combined with an unsanitized SRS parameter in WMS 1.3.0 requests. This issue has been patched in version 8.6.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42030?
CVE-2026-42030 is considered a medium severity reflected XSS vulnerability.
How do I fix CVE-2026-42030?
To fix CVE-2026-42030, upgrade MapServer to version 8.6.2 or later.
Who is affected by CVE-2026-42030?
CVE-2026-42030 affects all versions of MapServer from 6.0 up to, but not including, 8.6.2.
What type of vulnerability is CVE-2026-42030?
CVE-2026-42030 is classified as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2026-42030 be exploited remotely?
Yes, CVE-2026-42030 can be exploited remotely by an unauthenticated attacker through specially crafted requests.