Cross-Site Scripting in MapServer Affected by Malicious HTTP Header Manipulation
CVE-2026-54355

5.3MEDIUM

Key Information:

Vendor

Mapserver

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54355?

MapServer, a system for developing web-based Geographic Information Systems (GIS) applications, is prone to a Cross-Site Scripting (XSS) vulnerability due to improper handling of the X-Forwarded-Host HTTP header. The vulnerability arises from the OpenLayers HTML output generated for the WMS GetMap request, where attacker-controlled values are not adequately escaped in JavaScript strings. If exploited, this flaw allows an unauthenticated attacker to craft malicious URLs that execute arbitrary JavaScript in the context of the MapServer site, potentially compromising user sessions or sensitive data. The issue has been rectified in version 8.6.4.

Affected Version(s)

MapServer >= 6.0, < 8.6.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.