CVE-2026-55848

Source
https://cve.org/CVERecord?id=CVE-2026-55848
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55848.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55848
Aliases
Published
2026-08-28T22:31:26.705Z
Modified
2026-09-01T03:46:09.186519198Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types
Details

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/print/map/geotools/GmlLayer.java without disabling external entities and external DTDs. A remote XML document and DTD can expand a local file entity, and the resulting content can be exposed through the GML parsing and error path. This allows unauthenticated attackers to read files such as operating-system account data, Kubernetes service-account tokens, and certificates. Replacing the file entity target with an internal HTTP endpoint also permits server-side request forgery. This issue is fixed in versions 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-611"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55848.json"
}
References

Affected packages

Git / github.com/mapfish/mapfish-print

Affected ranges

Type
GIT
Repo
https://github.com/mapfish/mapfish-print
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.28.30"
        },
        {
            "introduced": "3.29.0"
        },
        {
            "fixed": "3.30.32"
        },
        {
            "introduced": "3.31.0"
        },
        {
            "fixed": "3.31.24"
        },
        {
            "introduced": "3.32.0"
        },
        {
            "fixed": "3.33.16"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.23.0
3.24.0
3.27.0
3.28.0
3.28.1
3.28.10
3.28.11
3.28.12
3.28.13
3.28.14
3.28.15
3.28.16
3.28.17
3.28.18
3.28.19
3.28.20
3.28.21
3.28.22
3.28.23
3.28.24
3.28.25
3.28.26
3.28.27
3.28.28
3.28.29
3.28.3
3.28.4
3.28.5
3.28.6
3.28.8
3.28.9
3.30.0
3.30.1
3.30.10
3.30.11
3.30.12
3.30.13
3.30.14
3.30.15
3.30.16
3.30.17
3.30.18
3.30.19
3.30.2
3.30.20
3.30.21
3.30.22
3.30.23
3.30.24
3.30.25
3.30.26
3.30.27
3.30.28
3.30.29
3.30.3
3.30.30
3.30.31
3.30.5
3.30.6
3.30.7
3.31.1
3.31.10
3.31.11
3.31.12
3.31.13
3.31.14
3.31.15
3.31.16
3.31.17
3.31.18
3.31.19
3.31.2
3.31.20
3.31.21
3.31.22
3.31.23
3.31.3
3.31.4
3.31.5
3.31.6
3.31.7
3.31.8
3.31.9
3.32.0
3.33.0
3.33.1
3.33.10
3.33.11
3.33.12
3.33.13
3.33.14
3.33.15
3.33.2
3.33.3
3.33.4
3.33.5
3.33.6
3.33.7
3.33.8
3.33.9
4.*
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
release/3.*
release/3.0.0
release/3.1.2
release/3.10.0
release/3.10.1
release/3.10.2
release/3.11.0
release/3.11.1
release/3.11.2
release/3.11.3
release/3.12.0
release/3.12.1
release/3.13.0
release/3.14.0
release/3.14.1
release/3.15.0
release/3.16.0
release/3.16.1
release/3.16.2
release/3.17.0
release/3.18.0
release/3.18.1
release/3.18.2
release/3.18.3
release/3.18.4
release/3.19.0
release/3.19.1
release/3.2.0
release/3.20.0
release/3.20.1
release/3.21.0
release/3.22.0
release/3.23
release/3.23.0
release/3.24.0
release/3.25.0
release/3.27.0
release/3.28.0
release/3.28.1
release/3.28.4
release/3.3.0
release/3.4.0
release/3.5.0
release/3.6.0
release/3.7.0
release/3.8.0
release/3.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55848.json"