CVE-2026-54355

Source
https://cve.org/CVERecord?id=CVE-2026-54355
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54355.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54355
Aliases
  • GHSA-xqj6-vjqr-33vv
Published
2026-09-17T20:24:32Z
Modified
2026-09-19T08:08:56Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`
Details

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(), and the [mapserv_onlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed ows_onlineresource or MS_ONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54355.json"
}
References

Affected packages

Git / github.com/mapserver/mapserver

Affected ranges

Type
GIT
Repo
https://github.com/mapserver/mapserver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.0"
        },
        {
            "fixed": "8.6.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54355.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "90448607702931688131323002727052899696",
            "length": 1058
        },
        "id": "CVE-2026-54355-00f57082",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
        "target": {
            "file": "src/mapstring.cpp",
            "function": "msEscapeJSonString"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "8546012091672940196754749308373961722",
                "318975916114461424727842726716099678880",
                "246398557391581334965395408501806208115",
                "336868569705453870523488399798535061499"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-0268dfb3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
        "target": {
            "file": "src/maptemplate.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "336996951734291086862943129712390705578",
                "106576489250400136934926862779282098152",
                "238080962809700700264428206605518876555",
                "55774262522654096044914431896213673845"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-1b349fbd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
        "target": {
            "file": "src/mapserver.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "282579690342835435199191757369981508428",
                "291178078620448435042837599630823243535",
                "12088643364784871826599756675764955459",
                "169467465892404789119133928206270977730",
                "115384861410415783659794456516689446783",
                "330448904572042159339978963733334718825",
                "276106342826967755053555726920987778260",
                "1465860264213467734574088382865329748",
                "87564840708283619318473483605683408890",
                "292011723129926043301756686904237463170",
                "3476944301923922364524784180666795217",
                "118908801315783162997748945656043608481",
                "239505236317636725699157122217711092024",
                "27643217464612694467928728789633263963",
                "127460349743560039391294672385776180324",
                "99172488628825068301065163878609380029",
                "212516783063133041229858663160407111091",
                "78318089299735315619654304459548603018",
                "158672067220707423731813834610728143532"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-3a720928",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
        "target": {
            "file": "src/mapstring.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "282579690342835435199191757369981508428",
                "291178078620448435042837599630823243535",
                "12088643364784871826599756675764955459",
                "169467465892404789119133928206270977730",
                "115384861410415783659794456516689446783",
                "330448904572042159339978963733334718825",
                "276106342826967755053555726920987778260",
                "1465860264213467734574088382865329748",
                "87564840708283619318473483605683408890",
                "292011723129926043301756686904237463170",
                "3476944301923922364524784180666795217",
                "118908801315783162997748945656043608481",
                "239505236317636725699157122217711092024",
                "27643217464612694467928728789633263963",
                "127460349743560039391294672385776180324",
                "99172488628825068301065163878609380029",
                "212516783063133041229858663160407111091",
                "78318089299735315619654304459548603018",
                "158672067220707423731813834610728143532"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-975b6006",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
        "target": {
            "file": "src/mapstring.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "90448607702931688131323002727052899696",
            "length": 1058
        },
        "id": "CVE-2026-54355-982e7aef",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
        "target": {
            "file": "src/mapstring.cpp",
            "function": "msEscapeJSonString"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "308240233515577154463122133307189983868",
            "length": 20202
        },
        "id": "CVE-2026-54355-adf81eca",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
        "target": {
            "file": "src/maptemplate.c",
            "function": "processLine"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "8546012091672940196754749308373961722",
                "318975916114461424727842726716099678880",
                "246398557391581334965395408501806208115",
                "336868569705453870523488399798535061499"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-d4395a41",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e",
        "target": {
            "file": "src/maptemplate.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "308240233515577154463122133307189983868",
            "length": 20202
        },
        "id": "CVE-2026-54355-f8a63c24",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
        "target": {
            "file": "src/maptemplate.c",
            "function": "processLine"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "336996951734291086862943129712390705578",
                "106576489250400136934926862779282098152",
                "238080962809700700264428206605518876555",
                "55774262522654096044914431896213673845"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54355-ffa44226",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374",
        "target": {
            "file": "src/mapserver.h"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:08:56Z"