[MapServer-dev] MapServer and security/CVEs

Seth G sethg at geographika.co.uk
Fri Aug 21 05:45:52 PDT 2026


Hi all,

There is an open PR at https://github.com/MapServer/MapServer/pull/7525 that adds a new fuzzer for testing the WxS requests. It is fairly limited in scope (only GET requests, so no POST/XML testing, and using a Mapfile without any layers). I am ok with doing a triage of any issues raised by this fuzzer, and hopefully fixing them. Unless there are any objections then I'll merge this. 

On a related note, there are currently 16 open security advisories: https://github.com/MapServer/MapServer/security/advisories
As I understand it these are never made public by GitHub (unlike 90-day OSS-Fuzz disclosure policy), but a reporter may make it public outside of GitHub themselves (and even get a CVE). 
Does the advisory approach still make sense now the number of reported issues has exploded (see slide at https://geographika.github.io/mapserver-state-2026/#/2/1)?

Maybe we should just move them to standard issues after a few months. On the outstanding list I think several are very low priority or could already be classed as issues. None of the remaining ones relate to projects or areas of MapServer I'm interested in (I'm not a PostGIS or Oracle user, or worried about corrupt DBFs). Maybe if made public other users may pick these up, or at least provide funding for a fix.

Interested in people's thoughts,

Seth


--
web:https://geographika.net & https://mapserverstudio.net
mastodon: @geographika at mastodon.social


More information about the MapServer-dev mailing list