Input validation error in MapServer - #VU146013

 

Input validation error in MapServer - #VU146013

Published: August 27, 2026


Vulnerability identifier: #VU146013
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the WCS 2.0 GetCoverage request handling when processing the RESOLUTION parameter. A remote attacker can send a specially crafted request with a non-positive RESOLUTION value to cause a denial of service.

A negative RESOLUTION value can terminate the handling CGI or FastCGI worker via exit(1), and repeated requests can deplete the worker pool.


Affected software

MapServer

Remediation

Install security update from vendor's website.

MapServer - update to 4.4.1

External References

Related Security Bulletins