Description
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(), and the [mapserv_onlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed ows_onlineresource or MS_ONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected XSS
Action: Patch
AI Analysis

Impact

MapServer generates OpenLayers HTML for GetMap requests that reflect the HTTP_X_FORWARDED_HOST header into a single‑quoted JavaScript string without escaping. This flaw allows an attacker to inject malicious JavaScript that will run in a victim’s browser when the victim accesses a crafted URL, enabling theft of session cookies, reading same‑origin data, and performing actions as the user. The weakness is an improper input validation issue, classified as CWE‑79.

Affected Systems

MapServer (MapServer) versions from 6.0 through 8.6.3 are affected. The vulnerability is triggered only when the deployment trusts the X‑Forwarded‑Host header and does not set a fixed ows_onlineresource or MS_ONLINERESOURCE value.

Risk and Exploitability

The CVSS score of 5.3 and an EPSS score of less than 1 % indicate a moderate severity with a low likelihood of exploitation. The likely attack vector is a malicious link or malicious proxy that supplies a crafted X‑Forwarded‑Host header. Based on the description, it is inferred that the attacker can embed single quotes to break out of the JavaScript string and trigger reflected XSS. The vulnerability is not listed in the CISA KEV catalog, but an unauthenticated attacker who can influence the forwarded header can exploit the flaw within the site’s own origin.

Generated by OpenCVE AI on September 19, 2026 at 02:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MapServer to version 8.6.4 or later to apply the vendor fix
  • Configure a static ows_onlineresource or MS_ONLINERESOURCE value and disable trust in the X‑Forwarded‑Host header if an upgrade is not immediately possible
  • Ensure any reverse proxy or HTTP server sanitizes or rejects the X‑Forwarded‑Host header to prevent injection

Generated by OpenCVE AI on September 19, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mapserver
Mapserver mapserver
Vendors & Products Mapserver
Mapserver mapserver

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(), and the [mapserv_onlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed ows_onlineresource or MS_ONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.
Title MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Mapserver Mapserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:45:56.071Z

Reserved: 2026-06-12T19:23:22.318Z

Link: CVE-2026-54355

cve-icon Vulnrichment

Updated: 2026-09-24T20:45:43.871Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:15.410

Modified: 2026-09-30T17:23:08.953

Link: CVE-2026-54355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')