Ad

CVE-2026-33721

HIGH CVSS 3.1: 7.5 EPSS 0.19%
Updated Apr 17, 2026
Mapserver
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 4.2.0 — 8.6.1
Fixed In 8.6.1
Type CWE-787 (Out-of-bounds Write)
Vendor Mapserver
Public PoC No

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLD_BODY). Version 8.6.1 patches the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Osgeo Mapserver
cpe:2.3:a:osgeo:mapserver:*:*:*:*:*:*:*:*
4.2.0 8.6.1