PT-2026-28511 · Mapserver · Mapserver

·

CVE-2026-33721

·

Published

2026-03-23

·

Updated

2026-03-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MapServer versions 4.2 through 8.6.0
Description MapServer is a system for developing web-based GIS applications. A heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser allows a remote, unauthenticated attacker to crash the MapServer process. This occurs by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure, commonly reachable via WMS GetMap with the SLD BODY parameter. The vulnerable component is the SLD parser.
Recommendations Update to MapServer version 8.6.1 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12080
CVE-2026-33721
GHSA-CV4M-MR84-FGJP
OPENSUSE-SU-2026:10452-1
OPENSUSE-SU-2026:20476-1
OPENSUSE-SU-2026:20857-1

Affected Products

Mapserver