Cross-Site Scripting in MapServer Affected by Malicious HTTP Header Manipulation
CVE-2026-54355
5.3MEDIUM
What is CVE-2026-54355?
MapServer, a system for developing web-based Geographic Information Systems (GIS) applications, is prone to a Cross-Site Scripting (XSS) vulnerability due to improper handling of the X-Forwarded-Host HTTP header. The vulnerability arises from the OpenLayers HTML output generated for the WMS GetMap request, where attacker-controlled values are not adequately escaped in JavaScript strings. If exploited, this flaw allows an unauthenticated attacker to craft malicious URLs that execute arbitrary JavaScript in the context of the MapServer site, potentially compromising user sessions or sensitive data. The issue has been rectified in version 8.6.4.
Affected Version(s)
MapServer >= 6.0, < 8.6.4
