Uncontrolled Memory Allocation in MapServer - #VU147314
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to insufficient validation of image dimensions in msWMSLoadGetMapParams() when handling WMS GetMap requests that request in-image exceptions and trigger an early error. A remote attacker can submit a WMS GetMap request with oversized WIDTH and HEIGHT values to cause a denial of service.
A valid layer name and knowledge of the target mapfile are not required.