{"id":"CVE-2026-55848","summary":"mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types","details":"mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/print/map/geotools/GmlLayer.java without disabling external entities and external DTDs. A remote XML document and DTD can expand a local file entity, and the resulting content can be exposed through the GML parsing and error path. This allows unauthenticated attackers to read files such as operating-system account data, Kubernetes service-account tokens, and certificates. Replacing the file entity target with an internal HTTP endpoint also permits server-side request forgery. This issue is fixed in versions 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5.","aliases":["GHSA-5v29-34h8-v68r"],"modified":"2026-09-01T03:46:09.186519198Z","published":"2026-08-28T22:31:26.705Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55848.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-611"]},"references":[{"type":"WEB","url":"https://github.com/mapfish/mapfish-print/releases/tag/3.28.30"},{"type":"WEB","url":"https://github.com/mapfish/mapfish-print/releases/tag/3.30.32"},{"type":"WEB","url":"https://github.com/mapfish/mapfish-print/releases/tag/3.31.24"},{"type":"WEB","url":"https://github.com/mapfish/mapfish-print/releases/tag/4.0.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55848.json"},{"type":"ADVISORY","url":"https://github.com/mapfish/mapfish-print/security/advisories/GHSA-5v29-34h8-v68r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55848"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/13beae7a7f970fc3526c1f7ca5db817d8d51fbec"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/23a96e7baa15077bdb0e5fc5a72b18da23af9121"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/3525e8150fcb5f40095930ccf7aec0d8ce92bbcb"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/56c47d3bf70d8428916dea8ed7005518ad07dc7d"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/a55a24873db5f19b37abac7d59144dc86406c236"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/commit/d13911ac6e0509444d64e74830f10b14e4dcfdf1"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4212"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4215"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4216"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4217"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4219"},{"type":"FIX","url":"https://github.com/mapfish/mapfish-print/pull/4221"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mapfish/mapfish-print","events":[{"introduced":"4cbdc47c7e96ac47108806e8ea11d6da8bfcbdfc"},{"introduced":"0"},{"introduced":"b4183098cf4df8e3baffdcb2757bb1f0a6c76853"},{"introduced":"8d40689f579921a1e8cc217fb96dff216924408e"},{"fixed":"cc2528102837a6034470f2bf7e08e6181ed62d7d"},{"fixed":"f199a1d934cefc514fadf3c669e37283f3affd13"},{"fixed":"72159c9881aaf6b0352a977017c4e40f261b4553"},{"fixed":"c46a36e99e648994358832782875895334b1868d"},{"fixed":"60ab2dc4bb49d6cda4210bbe62a3fb9ceeef8c87"},{"fixed":"13beae7a7f970fc3526c1f7ca5db817d8d51fbec"},{"fixed":"23a96e7baa15077bdb0e5fc5a72b18da23af9121"},{"fixed":"3525e8150fcb5f40095930ccf7aec0d8ce92bbcb"},{"fixed":"56c47d3bf70d8428916dea8ed7005518ad07dc7d"},{"fixed":"a55a24873db5f19b37abac7d59144dc86406c236"},{"fixed":"d13911ac6e0509444d64e74830f10b14e4dcfdf1"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.28.30"},{"introduced":"3.29.0"},{"fixed":"3.30.32"},{"introduced":"3.31.0"},{"fixed":"3.31.24"},{"introduced":"3.32.0"},{"fixed":"3.33.16"},{"introduced":"4.0.0"},{"fixed":"4.0.5"}]}}],"versions":["3.30.30","3.30.31","3.28.29","3.31.23","4.0.4","3.33.15","4.0.3","3.31.22","3.33.14","3.28.28","3.30.29","3.28.27","3.33.13","3.31.21","4.0.2","3.30.28","4.0.1","3.31.20","3.33.12","3.28.26","4.0.0","3.30.27","3.28.25","3.33.11","3.31.19","3.33.10","3.30.26","3.28.24","3.31.18","3.33.9","3.30.25","3.28.23","3.31.17","3.33.8","3.31.16","3.30.24","3.33.7","3.28.22","3.33.6","3.30.23","3.28.21","3.33.5","3.31.15","3.28.20","3.31.14","3.33.4","3.30.22","3.33.3","3.28.19","3.31.13","3.30.21","3.33.2","3.30.20","3.28.18","3.33.1","3.31.12","3.30.19","3.33.0","3.28.17","3.31.11","3.32.0","3.30.18","3.28.16","3.31.10","3.30.17","3.28.15","3.31.5","3.31.9","3.30.16","3.28.14","3.31.8","3.28.13","3.31.7","3.30.15","3.28.12","3.30.14","3.31.6","3.30.13","3.28.11","3.31.4","3.30.12","3.31.3","3.31.2","3.28.10","3.31.1","3.30.11","3.28.9","3.28.8","3.30.10","3.30.7","3.30.6","3.28.6","3.30.5","3.30.3","3.30.2","3.30.1","3.30.0","release/3.23","3.23.0","3.28.5","release/3.28.4","3.28.4","3.28.3","release/3.27.0","3.27.0","release/3.28.1","3.28.1","release/3.28.0","3.28.0","release/3.25.0","release/3.24.0","3.24.0","release/3.23.0","release/3.22.0","release/3.19.1","release/3.18.4","release/3.17.0","release/3.16.2","release/3.15.0","release/3.21.0","release/3.20.1","release/3.20.0","release/3.19.0","release/3.18.3","release/3.18.2","release/3.18.1","release/3.18.0","release/3.16.1","release/3.16.0","release/3.14.1","release/3.14.0","release/3.13.0","release/3.12.1","release/3.12.0","release/3.11.3","release/3.11.2","release/3.11.1","release/3.11.0","release/3.10.2","release/3.10.1","release/3.10.0","release/3.7.0","release/3.9.0","release/3.8.0","release/3.6.0","release/3.5.0","release/3.4.0","release/3.3.0","release/3.2.0","release/3.1.2","release/3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55848.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}