Uncontrolled Recursion in MapServer - #VU146016
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the WMS GetMap FILTER parser and processing path when handling a crafted FILTER parameter containing an
The issue is triggered before any map image is produced and does not depend on valid data or matching records, but it requires a WMS layer that accepts a FILTER parameter.