NULL pointer dereference in MapServer - CVE-2026-45104
Published: May 11, 2026
MapServer
MapServer
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in msSLDParseUserStyle and _SLDApplyRuleValues in MapServer SLD support when processing a crafted SLD ElseFilter rule through the WMS SLD_BODY parameter. A remote attacker can send a specially crafted SLD payload to cause a denial of service.
The issue is reachable through the WMS handler without authentication, and long-lived deployments such as FastCGI, mod_mapserver, or MapScript bindings may terminate the serving process for unrelated in-flight requests.