{"id":"CVE-2026-54355","summary":"MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`","details":"MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(), and the [mapserv_onlineresource] substitution in src/maputil.c and src/maptemplate.c without escaping it for a single-quoted JavaScript string. When the deployment trusts the forwarded header and does not configure a fixed ows_onlineresource or MS_ONLINERESOURCE value, embedded single quotes can escape the generated URL string. An unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the MapServer site origin when opened by a victim, enabling access to sessions or tokens, same-origin data and requests, and actions as the victim. This issue is fixed in version 8.6.4.","aliases":["GHSA-xqj6-vjqr-33vv"],"modified":"2026-09-19T08:08:56.907302Z","published":"2026-09-17T20:24:32.522Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54355.json"},"references":[{"type":"WEB","url":"https://github.com/MapServer/MapServer/releases/tag/rel-8-6-4"},{"type":"WEB","url":"https://mapserver.org/development/changelog/changelog-8-6.html#changelog-8-6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54355.json"},{"type":"ADVISORY","url":"https://github.com/MapServer/MapServer/security/advisories/GHSA-xqj6-vjqr-33vv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54355"},{"type":"FIX","url":"https://github.com/MapServer/MapServer/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374"},{"type":"FIX","url":"https://github.com/MapServer/MapServer/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e"},{"type":"FIX","url":"https://github.com/MapServer/MapServer/pull/7517"},{"type":"FIX","url":"https://github.com/MapServer/MapServer/pull/7518"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mapserver/mapserver","events":[{"introduced":"a7e04b01eab44f9f027fab5f1081eb18d9453212"},{"fixed":"edc1033c7963fcffd160d85cf430f49aaf4a1374"},{"fixed":"ff17ef190caaeaa9002ac3d1c7969ec5315c345e"},{"fixed":"b7896ad27b553403868e2cbb2710cc4b5fdcd4c8"}],"database_specific":{"extracted_events":[{"introduced":"6.0"},{"fixed":"8.6.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54355.json","vanir_signatures_modified":"2026-09-19T08:08:56Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374","target":{"file":"src/mapstring.cpp","function":"msEscapeJSonString"},"deprecated":false,"digest":{"function_hash":"90448607702931688131323002727052899696","length":1058},"id":"CVE-2026-54355-00f57082","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374","target":{"file":"src/maptemplate.c"},"deprecated":false,"digest":{"line_hashes":["8546012091672940196754749308373961722","318975916114461424727842726716099678880","246398557391581334965395408501806208115","336868569705453870523488399798535061499"],"threshold":0.9},"id":"CVE-2026-54355-0268dfb3"},{"source":"https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e","target":{"file":"src/mapserver.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["336996951734291086862943129712390705578","106576489250400136934926862779282098152","238080962809700700264428206605518876555","55774262522654096044914431896213673845"]},"id":"CVE-2026-54355-1b349fbd","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["282579690342835435199191757369981508428","291178078620448435042837599630823243535","12088643364784871826599756675764955459","169467465892404789119133928206270977730","115384861410415783659794456516689446783","330448904572042159339978963733334718825","276106342826967755053555726920987778260","1465860264213467734574088382865329748","87564840708283619318473483605683408890","292011723129926043301756686904237463170","3476944301923922364524784180666795217","118908801315783162997748945656043608481","239505236317636725699157122217711092024","27643217464612694467928728789633263963","127460349743560039391294672385776180324","99172488628825068301065163878609380029","212516783063133041229858663160407111091","78318089299735315619654304459548603018","158672067220707423731813834610728143532"]},"id":"CVE-2026-54355-3a720928","signature_type":"Line","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374","target":{"file":"src/mapstring.cpp"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e","target":{"file":"src/mapstring.cpp"},"deprecated":false,"digest":{"line_hashes":["282579690342835435199191757369981508428","291178078620448435042837599630823243535","12088643364784871826599756675764955459","169467465892404789119133928206270977730","115384861410415783659794456516689446783","330448904572042159339978963733334718825","276106342826967755053555726920987778260","1465860264213467734574088382865329748","87564840708283619318473483605683408890","292011723129926043301756686904237463170","3476944301923922364524784180666795217","118908801315783162997748945656043608481","239505236317636725699157122217711092024","27643217464612694467928728789633263963","127460349743560039391294672385776180324","99172488628825068301065163878609380029","212516783063133041229858663160407111091","78318089299735315619654304459548603018","158672067220707423731813834610728143532"],"threshold":0.9},"id":"CVE-2026-54355-975b6006"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e","target":{"file":"src/mapstring.cpp","function":"msEscapeJSonString"},"deprecated":false,"digest":{"function_hash":"90448607702931688131323002727052899696","length":1058},"id":"CVE-2026-54355-982e7aef"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e","target":{"file":"src/maptemplate.c","function":"processLine"},"deprecated":false,"digest":{"function_hash":"308240233515577154463122133307189983868","length":20202},"id":"CVE-2026-54355-adf81eca"},{"signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/ff17ef190caaeaa9002ac3d1c7969ec5315c345e","target":{"file":"src/maptemplate.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["8546012091672940196754749308373961722","318975916114461424727842726716099678880","246398557391581334965395408501806208115","336868569705453870523488399798535061499"]},"id":"CVE-2026-54355-d4395a41","signature_type":"Line"},{"id":"CVE-2026-54355-f8a63c24","signature_type":"Function","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374","target":{"file":"src/maptemplate.c","function":"processLine"},"deprecated":false,"digest":{"function_hash":"308240233515577154463122133307189983868","length":20202}},{"deprecated":false,"digest":{"line_hashes":["336996951734291086862943129712390705578","106576489250400136934926862779282098152","238080962809700700264428206605518876555","55774262522654096044914431896213673845"],"threshold":0.9},"id":"CVE-2026-54355-ffa44226","signature_type":"Line","signature_version":"v1","source":"https://github.com/mapserver/mapserver/commit/edc1033c7963fcffd160d85cf430f49aaf4a1374","target":{"file":"src/mapserver.h"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}