PT-2026-28511 · Mapserver · Mapserver

Kevin-Valerio

·

Published

2026-03-27

·

Updated

2026-03-28

·

CVE-2026-33721

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MapServer versions 4.2 through 8.6.0
Description MapServer is a system for developing web-based GIS applications. A heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser allows a remote, unauthenticated attacker to crash the MapServer process. This occurs by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure, commonly reachable via WMS GetMap with the SLD BODY parameter. The vulnerable component is the SLD parser.
Recommendations Update to MapServer version 8.6.1 or later.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-33721
GHSA-CV4M-MR84-FGJP
OPENSUSE-SU-2026:10452-1
OPENSUSE-SU-2026:20476-1
OPENSUSE-SU-2026:20857-1

Affected Products

Mapserver