


Perceptive Security
SOC/SIEM Consultancy

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLaye…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 21:06:41
Source:
nvd.nist.gov
Web Technologies
CVE-2026-45104 affects MapServer versions 6.4.0 to before 8.6.3. The vulnerability occurs in msSLDParseUserStyle function when processing SLD rules with ElseFilter but no symbolizer. This causes a NULL pointer dereference when _SLDApplyRuleValues attempts to index _class[-1]. The vulnerability can be triggered with a 200-byte well-formed SLD via WMS SLD_BODY parameter without authentication. The issue is fixed in MapServer version 8.6.3.
Technical details
Mitigation steps:
Affected products:
MapServer
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45104
https://github.com/MapServer/MapServer/security/advisories/GHSA-4h8g-378q-r75m
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
