[MapServer-dev] MapServer and security/CVEs
Jeff McKenna
jmckenna at gatewaygeomatics.com
Fri Aug 21 06:25:16 PDT 2026
Hi Seth,
Regarding security reports, as you know, I had been triaging the new
security advisories, and, after the dust has settled now from the 8.6.5
release (it was a big push), I have been meaning to restart the triage
process (I tend to tackle these for each upcoming release). Now with
the 8.6.6 release needed again (there is an important fix committed to
branch-8-6 for SVG users), I will go through the pending advisories.
I am also ok with moving low priority reports to regular issues.
Let's begin the triage, again :)
-jeff
On 2026-08-21 9:45 a.m., Seth G via MapServer-dev wrote:
> Hi all,
>
> There is an open PR at https://github.com/MapServer/MapServer/pull/7525 that adds a new fuzzer for testing the WxS requests. It is fairly limited in scope (only GET requests, so no POST/XML testing, and using a Mapfile without any layers). I am ok with doing a triage of any issues raised by this fuzzer, and hopefully fixing them. Unless there are any objections then I'll merge this.
>
> On a related note, there are currently 16 open security advisories: https://github.com/MapServer/MapServer/security/advisories
> As I understand it these are never made public by GitHub (unlike 90-day OSS-Fuzz disclosure policy), but a reporter may make it public outside of GitHub themselves (and even get a CVE).
> Does the advisory approach still make sense now the number of reported issues has exploded (see slide at https://geographika.github.io/mapserver-state-2026/#/2/1)?
>
> Maybe we should just move them to standard issues after a few months. On the outstanding list I think several are very low priority or could already be classed as issues. None of the remaining ones relate to projects or areas of MapServer I'm interested in (I'm not a PostGIS or Oracle user, or worried about corrupt DBFs). Maybe if made public other users may pick these up, or at least provide funding for a fix.
>
> Interested in people's thoughts,
>
> Seth
>
>
More information about the MapServer-dev
mailing list