XML Parsing Vulnerability in MapFish Print Component by MapFish
CVE-2026-55848

8.6HIGH

What is CVE-2026-55848?

The MapFish Print component, utilized for generating templated cartographic maps, is susceptible to an XML External Entity (XXE) vulnerability before versions 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5. It allows attackers to manipulate GML layer URLs, leading the system to fetch and parse remote XML documents and DTDs without proper security measures in place. This vulnerability can lead to exposure of sensitive files, including operating system account details and Kubernetes service tokens. Additionally, attackers can exploit this vulnerability to facilitate server-side request forgery (SSRF) attacks.

Affected Version(s)

mapfish-print >= 3.0.0, < 3.28.30 < 3.0.0, 3.28.30

mapfish-print >= 3.29.0, < 3.30.32 < 3.29.0, 3.30.32

mapfish-print >= 3.31.0, < 3.31.24 < 3.31.0, 3.31.24

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.