Memory-Safety Fault in Adaguc-Server Affects Geospatial Data Processing
CVE-2026-50126
4MEDIUM
What is CVE-2026-50126?
Adaguc-Server, an open-source geographic information system, is susceptible to a memory-safety fault when processing malformed GeoJSON documents. Specifically, versions prior to 7.2.2 fail to properly validate the geometry coordinates during parsing, allowing for out-of-bounds heap reads or null pointer dereferences. This vulnerability can be exploited when the server processes local GeoJSON files, including those configured or requested through the AutoResource feature via unauthenticated WMS requests. A specially crafted GeoJSON document can lead to the backend process crashing, highlighting the importance of upgrading to version 7.2.2, which addresses these security concerns.
Affected Version(s)
adaguc-server < 7.2.2
