MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml<item>type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId input is a numeric literal. The unquoted input is concatenated into the generated PostgreSQL/PostGIS predicate, allowing an unauthenticated remote attacker with access to an affected query endpoint to bypass predicates, enumerate unintended records, perform boolean-based or time-based SQL injection, and increase database load. The issue does not by itself establish database modification capabilities. This issue is fixed in version 8.6.4.
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLDBODY). Version 8.6.1 patches the issue.
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When the rule has no symbolizer (a structurally valid SLD), msSLDParseRule adds zero, and SLDApplyRuleValues ends up indexing class[-1], resulting in a NULL pointer dereference. A 200-byte well-formed SLD via the WMS SLDBODY= parameter is enough to trigger this, no auth required. This vulnerability is fixed in 8.6.3.
MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary HTML/JavaScript into the browser of any user who opens a crafted WMS URL. The vulnerability is triggered via FORMAT=application/openlayers combined with an unsanitized SRS parameter in WMS 1.3.0 requests. This issue has been patched in version 8.6.2.
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTPXFORWARDEDHOST through msBuildOnlineResource(), processLine(), and the [mapservonlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed owsonlineresource or MSONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.
-------------------- Start of forwarded message -------------------- Date: Sun, 6 Sep 2026 17:06:51 -0300 To: mapserver-announce () lists osgeo org Subject: [mapserver-announce] security release available: MapServer 8.6.6 From: Jeff McKenna via MapServer-announce <mapserver-announce () lists osgeo org>
The MapServer team announces the immediate availability of security release of 8.6.6
This release contains a fix for 6 vulnerabilities. See the changelog for the list of changes ( https://mapserver.org/development/changelog/changelog-8-6.html#changelog-8-6-6 ).
You may also review the security advisories for this release: - WCS 2.0 support advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-6jr5-rc9c-p3cj - CGI/FastCGI with SMOOTHSIA advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-33h3-f4q2-pq5q - WMS Filter advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-5fx4-vjp9-863f - WMS with interpolation layers: https://github.com/MapServer/MapServer/security/advisories/GHSA-59gr-4vvx-5f56 - FlatGeobuf support : https://github.com/MapServer/MapServer/security/advisories/GHSA-5v7w-325g-gpr9 - WMS error image: https://github.com/MapServer/MapServer/security/advisories/GHSA-qcjf-q672-q63w
The 8.6.6 release also fixes a problem of SVG scaling that had existed since the 8.6.0 release, for those leveraging an older librsvg version (see https://github.com/MapServer/MapServer/pull/7583 ).
Please note: as security support for the 7.6 branch has ended, and branches 8.4, 8.2 & 8.0 are not supported, all users are strongly encouraged to upgrade to the MapServer 8.6.6 release.
Here is the direct download for today's release:
- tar.gz: https://download.osgeo.org/mapserver/mapserver-8.6.6.tar.gz - zip: https://download.osgeo.org/mapserver/mapserver-8.6.6.zip
(all services on demo.mapserver.org have been upgraded as well)
Thanks,
-- The MapServer Team
MapServer-announce mailing list MapServer-announce () lists osgeo org https://lists.osgeo.org/mailman/listinfo/mapserver-announce -------------------- End of forwarded message --------------------