GeoLens 1.2.4 fixes a set of vulnerabilities, the most serious of which allow authenticated or anonymous users to obtain data and metadata for datasets they are not authorized to access.
Cache-Control: public) headers, so a shared cache (a CDN or the bundled reverse proxy) could retain private tile bytes and replay them to later unauthenticated requests, including unpublished public-dataset previews./proc/<pid>/environ and allowing CRLF header injection.POST /search did not cap the size of GeoJSON intersects geometries (the GET sibling did).api_key query-string credential in cleartext.LOG_JSON logging flag rather than an explicit environment setting, so a production deployment at the default could expose /docs and emit a non-Secure session cookie.script-src/default-src CSP, leaving no containment for token exfiltration if an XSS issue were introduced.Upgrade to GeoLens 1.2.4. No configuration changes are required for the authorization and cache fixes. Operators on a public, TLS-terminated deployment should additionally set ENVIRONMENT=production to make the production security posture explicit; deployments that do not set it retain their prior behavior.
None for the authorization/cache disclosure flaws — upgrading is required. The SSRF and STAC-DoS surfaces can be partially mitigated at the network/proxy layer (egress filtering to block link-local metadata addresses; a request-size limit on POST /search), but the code fix is the durable remedy.
{
"cwe_ids": [
"CWE-1021",
"CWE-1392",
"CWE-200",
"CWE-285",
"CWE-400",
"CWE-524",
"CWE-532",
"CWE-918",
"CWE-93"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-19T19:22:59Z",
"nvd_published_at": null,
"severity": "HIGH"
}