Memory-Safety Fault in Adaguc-Server Affects Geospatial Data Processing
CVE-2026-50126

4MEDIUM

Key Information:

Vendor

Knmi

Vendor
CVE Published:
18 August 2026

What is CVE-2026-50126?

Adaguc-Server, an open-source geographic information system, is susceptible to a memory-safety fault when processing malformed GeoJSON documents. Specifically, versions prior to 7.2.2 fail to properly validate the geometry coordinates during parsing, allowing for out-of-bounds heap reads or null pointer dereferences. This vulnerability can be exploited when the server processes local GeoJSON files, including those configured or requested through the AutoResource feature via unauthenticated WMS requests. A specially crafted GeoJSON document can lead to the backend process crashing, highlighting the importance of upgrading to version 7.2.2, which addresses these security concerns.

Affected Version(s)

adaguc-server < 7.2.2

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.