Where
-Infinity
0

Vendor Risk Score

See how mapserver compares to other vendors in security performance

View Risk Score →
Severity
5.3
XSS
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTPXFORWARDEDHOST through msBuildOnlineResource(), processLine(), and the [mapservonlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed owsonlineresource or MSONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.

First published (updated )
Severity
8.2
SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml<item>type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId input is a numeric literal. The unquoted input is concatenated into the generated PostgreSQL/PostGIS predicate, allowing an unauthenticated remote attacker with access to an affected query endpoint to bypass predicates, enumerate unintended records, perform boolean-based or time-based SQL injection, and increase database load. The issue does not by itself establish database modification capabilities. This issue is fixed in version 8.6.4.

First published (updated )

-------------------- Start of forwarded message -------------------- Date: Sun, 6 Sep 2026 17:06:51 -0300 To: mapserver-announce () lists osgeo org Subject: [mapserver-announce] security release available: MapServer 8.6.6 From: Jeff McKenna via MapServer-announce <mapserver-announce () lists osgeo org>

The MapServer team announces the immediate availability of security release of 8.6.6

This release contains a fix for 6 vulnerabilities. See the changelog for the list of changes ( https://mapserver.org/development/changelog/changelog-8-6.html#changelog-8-6-6 ).

You may also review the security advisories for this release: - WCS 2.0 support advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-6jr5-rc9c-p3cj - CGI/FastCGI with SMOOTHSIA advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-33h3-f4q2-pq5q - WMS Filter advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-5fx4-vjp9-863f - WMS with interpolation layers: https://github.com/MapServer/MapServer/security/advisories/GHSA-59gr-4vvx-5f56 - FlatGeobuf support : https://github.com/MapServer/MapServer/security/advisories/GHSA-5v7w-325g-gpr9 - WMS error image: https://github.com/MapServer/MapServer/security/advisories/GHSA-qcjf-q672-q63w

The 8.6.6 release also fixes a problem of SVG scaling that had existed since the 8.6.0 release, for those leveraging an older librsvg version (see https://github.com/MapServer/MapServer/pull/7583 ).

Please note: as security support for the 7.6 branch has ended, and branches 8.4, 8.2 & 8.0 are not supported, all users are strongly encouraged to upgrade to the MapServer 8.6.6 release.

Here is the direct download for today's release:

- tar.gz: https://download.osgeo.org/mapserver/mapserver-8.6.6.tar.gz - zip: https://download.osgeo.org/mapserver/mapserver-8.6.6.zip

(all services on demo.mapserver.org have been upgraded as well)

Thanks,

-- The MapServer Team

MapServer-announce mailing list MapServer-announce () lists osgeo org https://lists.osgeo.org/mailman/listinfo/mapserver-announce -------------------- End of forwarded message --------------------

Severity
7.5
Out-of-bounds Read, Null Pointer Dereference
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When the rule has no symbolizer (a structurally valid SLD), msSLDParseRule adds zero, and SLDApplyRuleValues ends up indexing class[-1], resulting in a NULL pointer dereference. A 200-byte well-formed SLD via the WMS SLDBODY= parameter is enough to trigger this, no auth required. This vulnerability is fixed in 8.6.3.

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary HTML/JavaScript into the browser of any user who opens a crafted WMS URL. The vulnerability is triggered via FORMAT=application/openlayers combined with an unsanitized SRS parameter in WMS 1.3.0 requests. This issue has been patched in version 8.6.2.

First published (updated )
Severity
7.5
EPSS
0.07%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLDBODY). Version 8.6.1 patches the issue.

First published (updated )
Severity
4
Buffer Overflow, SQL Injection

Multiple SQL injection flaws and one stack based buffer overflow flaw were found in MapServer: [1] http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html

More from [1]:

MapServer developers have discovered flaws in the OGC filter support in MapServer. That code is used in support of WFS, WMS-SLD and SOS specifications.

All versions may be susceptible to SQL injection under certain circumstances. The extent of the vulnerability depends on the MapServer version, relational database and mapfile configuration being used. All users are strongly encouraged to upgrade to these latest releases.

The 5.6.7 and 4.10.7 releases also address one significant potentially exploitable buffer overflow (6.0 branch is not vulneralble).

References: [1] http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html [2] http://trac.osgeo.org/mapserver/ticket/3903 [3] https://bugzilla.redhat.com/showbug.cgi?id=722545 [4] http://www.openwall.com/lists/oss-security/2011/07/19/11 (CVE Request)

Relevant upstream patches: [5] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39036.0.x.patch (for 6.0.x branch) [6] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.6.x.patch (for 5.6.x branch) [7] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.4.x.patch (for 5.4.x branch) [8] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.2.x.patch (for 5.2.x branch) [9] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.0.x.patch (for 5.0.x branch) [10] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39034.10.x.patch (for 4.10.x branch)

First published (updated )
Severity
4
Buffer Overflow

MapServer upstream during a security audit of MapServer v5.6 source code found a potential buffer overflow in the way MapServer generated unique temporary filenames. A local attacker could use this flaw to conduct denial of service attacks.

References: [1] http://trac.osgeo.org/mapserver/ticket/3484

Upstream patch (against 5-4 SVN branch): [2] http://trac.osgeo.org/mapserver/changeset/10310

Upstream patch (against trunk): [3] http://trac.osgeo.org/mapserver/changeset/10318

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203