See how mapserver compares to other vendors in security performance
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml<item>type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId input is a numeric literal. The unquoted input is concatenated into the generated PostgreSQL/PostGIS predicate, allowing an unauthenticated remote attacker with access to an affected query endpoint to bypass predicates, enumerate unintended records, perform boolean-based or time-based SQL injection, and increase database load. The issue does not by itself establish database modification capabilities. This issue is fixed in version 8.6.4.
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTPXFORWARDEDHOST through msBuildOnlineResource(), processLine(), and the [mapservonlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed owsonlineresource or MSONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.
-------------------- Start of forwarded message -------------------- Date: Sun, 6 Sep 2026 17:06:51 -0300 To: mapserver-announce () lists osgeo org Subject: [mapserver-announce] security release available: MapServer 8.6.6 From: Jeff McKenna via MapServer-announce <mapserver-announce () lists osgeo org>
The MapServer team announces the immediate availability of security release of 8.6.6
This release contains a fix for 6 vulnerabilities. See the changelog for the list of changes ( https://mapserver.org/development/changelog/changelog-8-6.html#changelog-8-6-6 ).
You may also review the security advisories for this release: - WCS 2.0 support advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-6jr5-rc9c-p3cj - CGI/FastCGI with SMOOTHSIA advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-33h3-f4q2-pq5q - WMS Filter advisory: https://github.com/MapServer/MapServer/security/advisories/GHSA-5fx4-vjp9-863f - WMS with interpolation layers: https://github.com/MapServer/MapServer/security/advisories/GHSA-59gr-4vvx-5f56 - FlatGeobuf support : https://github.com/MapServer/MapServer/security/advisories/GHSA-5v7w-325g-gpr9 - WMS error image: https://github.com/MapServer/MapServer/security/advisories/GHSA-qcjf-q672-q63w
The 8.6.6 release also fixes a problem of SVG scaling that had existed since the 8.6.0 release, for those leveraging an older librsvg version (see https://github.com/MapServer/MapServer/pull/7583 ).
Please note: as security support for the 7.6 branch has ended, and branches 8.4, 8.2 & 8.0 are not supported, all users are strongly encouraged to upgrade to the MapServer 8.6.6 release.
Here is the direct download for today's release:
- tar.gz: https://download.osgeo.org/mapserver/mapserver-8.6.6.tar.gz - zip: https://download.osgeo.org/mapserver/mapserver-8.6.6.zip
(all services on demo.mapserver.org have been upgraded as well)
Thanks,
-- The MapServer Team
MapServer-announce mailing list MapServer-announce () lists osgeo org https://lists.osgeo.org/mailman/listinfo/mapserver-announce -------------------- End of forwarded message --------------------
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When the rule has no symbolizer (a structurally valid SLD), msSLDParseRule adds zero, and SLDApplyRuleValues ends up indexing class[-1], resulting in a NULL pointer dereference. A 200-byte well-formed SLD via the WMS SLDBODY= parameter is enough to trigger this, no auth required. This vulnerability is fixed in 8.6.3.
MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary HTML/JavaScript into the browser of any user who opens a crafted WMS URL. The vulnerability is triggered via FORMAT=application/openlayers combined with an unsanitized SRS parameter in WMS 1.3.0 requests. This issue has been patched in version 8.6.2.
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLDBODY). Version 8.6.1 patches the issue.
MapServer upstream during a security audit of MapServer v5.6 source code found a potential buffer overflow in the way MapServer generated unique temporary filenames. A local attacker could use this flaw to conduct denial of service attacks.
References: [1] http://trac.osgeo.org/mapserver/ticket/3484
Upstream patch (against 5-4 SVN branch): [2] http://trac.osgeo.org/mapserver/changeset/10310
Upstream patch (against trunk): [3] http://trac.osgeo.org/mapserver/changeset/10318
Multiple SQL injection flaws and one stack based buffer overflow flaw were found in MapServer: [1] http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html
More from [1]:
MapServer developers have discovered flaws in the OGC filter support in MapServer. That code is used in support of WFS, WMS-SLD and SOS specifications.
All versions may be susceptible to SQL injection under certain circumstances. The extent of the vulnerability depends on the MapServer version, relational database and mapfile configuration being used. All users are strongly encouraged to upgrade to these latest releases.
The 5.6.7 and 4.10.7 releases also address one significant potentially exploitable buffer overflow (6.0 branch is not vulneralble).
References: [1] http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html [2] http://trac.osgeo.org/mapserver/ticket/3903 [3] https://bugzilla.redhat.com/showbug.cgi?id=722545 [4] http://www.openwall.com/lists/oss-security/2011/07/19/11 (CVE Request)
Relevant upstream patches: [5] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39036.0.x.patch (for 6.0.x branch) [6] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.6.x.patch (for 5.6.x branch) [7] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.4.x.patch (for 5.4.x branch) [8] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.2.x.patch (for 5.2.x branch) [9] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39035.0.x.patch (for 5.0.x branch) [10] http://trac.osgeo.org/mapserver/attachment/ticket/3903/ticket39034.10.x.patch (for 4.10.x branch)