Cross-site scripting in MapServer - CVE-2026-54355
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim\'s browser.
The vulnerability exists due to cross-site scripting in the OpenLayers HTML output when processing a WMS GetMap request with FORMAT=application/openlayers and an attacker-controlled X-Forwarded-Host value reaches HTTP_X_FORWARDED_HOST. A remote attacker can send a specially crafted request or crafted URL to execute arbitrary JavaScript in the victim\'s browser.
User interaction is required to open an attacker-crafted URL, and exploitation depends on deployments that pass externally controlled forwarded host headers to MapServer and do not override the generated online resource with a fixed trusted value.