Server-Side Request Forgery (SSRF) in MapServer - #VU147316

 

Server-Side Request Forgery (SSRF) in MapServer - #VU147316

Published: September 7, 2026


Vulnerability identifier: #VU147316
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform server-side request forgery.

The vulnerability exists due to improper restriction of server-side requests in the WMS GetMap, GetLegendGraphic, and GetStyles request handlers when processing an SLD parameter containing a URL. A remote attacker can send a crafted WMS request containing an attacker-controlled SLD URL to perform server-side request forgery.

The SLD functionality is enabled by default when the relevant metadata flag is unset.


Affected software

MapServer

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins