MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(), and the [mapserv_onlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed ows_onlineresource or MS_ONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54355.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54355.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "90448607702931688131323002727052899696",
"length": 1058
},
"id": "CVE-2026-54355-00f57082",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
"target": {
"file": "src/mapstring.cpp",
"function": "msEscapeJSonString"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"8546012091672940196754749308373961722",
"318975916114461424727842726716099678880",
"246398557391581334965395408501806208115",
"336868569705453870523488399798535061499"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-0268dfb3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
"target": {
"file": "src/maptemplate.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"336996951734291086862943129712390705578",
"106576489250400136934926862779282098152",
"238080962809700700264428206605518876555",
"55774262522654096044914431896213673845"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-1b349fbd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
"target": {
"file": "src/mapserver.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"282579690342835435199191757369981508428",
"291178078620448435042837599630823243535",
"12088643364784871826599756675764955459",
"169467465892404789119133928206270977730",
"115384861410415783659794456516689446783",
"330448904572042159339978963733334718825",
"276106342826967755053555726920987778260",
"1465860264213467734574088382865329748",
"87564840708283619318473483605683408890",
"292011723129926043301756686904237463170",
"3476944301923922364524784180666795217",
"118908801315783162997748945656043608481",
"239505236317636725699157122217711092024",
"27643217464612694467928728789633263963",
"127460349743560039391294672385776180324",
"99172488628825068301065163878609380029",
"212516783063133041229858663160407111091",
"78318089299735315619654304459548603018",
"158672067220707423731813834610728143532"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-3a720928",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
"target": {
"file": "src/mapstring.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"282579690342835435199191757369981508428",
"291178078620448435042837599630823243535",
"12088643364784871826599756675764955459",
"169467465892404789119133928206270977730",
"115384861410415783659794456516689446783",
"330448904572042159339978963733334718825",
"276106342826967755053555726920987778260",
"1465860264213467734574088382865329748",
"87564840708283619318473483605683408890",
"292011723129926043301756686904237463170",
"3476944301923922364524784180666795217",
"118908801315783162997748945656043608481",
"239505236317636725699157122217711092024",
"27643217464612694467928728789633263963",
"127460349743560039391294672385776180324",
"99172488628825068301065163878609380029",
"212516783063133041229858663160407111091",
"78318089299735315619654304459548603018",
"158672067220707423731813834610728143532"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-975b6006",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
"target": {
"file": "src/mapstring.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "90448607702931688131323002727052899696",
"length": 1058
},
"id": "CVE-2026-54355-982e7aef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
"target": {
"file": "src/mapstring.cpp",
"function": "msEscapeJSonString"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "308240233515577154463122133307189983868",
"length": 20202
},
"id": "CVE-2026-54355-adf81eca",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
"target": {
"file": "src/maptemplate.c",
"function": "processLine"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"8546012091672940196754749308373961722",
"318975916114461424727842726716099678880",
"246398557391581334965395408501806208115",
"336868569705453870523488399798535061499"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-d4395a41",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
"target": {
"file": "src/maptemplate.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "308240233515577154463122133307189983868",
"length": 20202
},
"id": "CVE-2026-54355-f8a63c24",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
"target": {
"file": "src/maptemplate.c",
"function": "processLine"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"336996951734291086862943129712390705578",
"106576489250400136934926862779282098152",
"238080962809700700264428206605518876555",
"55774262522654096044914431896213673845"
],
"threshold": 0.9
},
"id": "CVE-2026-54355-ffa44226",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
"target": {
"file": "src/mapserver.h"
}
}
]
"2026-09-19T08:08:56Z"