Vulnerabilidades em MapServer
6 resultadosAnálise Vexday
O MapServer apresenta 4 vulnerabilidades catalogadas, das quais 2 foram divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, reduzindo o risco imediato. A fraqueza dominante é improper input validation (CWE-129), típica de processamento inadequado de dados de entrada.
CVE-2026-33721MEDIUMMapServer has heap buffer overflow in SLD `Categorize` Threshold parsingEPSS 0.9%CVE-2025-59431HIGHMapServer - WFS XML Filter Query SQL injectionEPSS 0.4%CVE-2026-54354HIGHMapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query TranslationEPSS 0.4%CVE-2026-54355MEDIUMMapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`EPSS 0.4%CVE-2026-45104HIGHMapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`EPSS 0.3%CVE-2026-42030MEDIUMMapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in OpenLayers viewerEPSS 0.2%