MapServer
Platform for publishing spatial data and interactive maps
Five of MapServer's last six releases exist to fix security advisories.
◆Recent moves
- 29d ago
Six advisories fixed across OGC API, WCS, WMS and JOIN support
The largest security release in this window by some margin, spanning OGC API Features, WCS, the OpenLayers viewer, GetLegendGraphic and both MySQL and PostgreSQL JOIN paths. Six advisories in one release points at a coordinated audit rather than individual reports.
View source ↗ - 2mo ago
Security release: OpenLayers viewer and PostGIS advisories
Two advisories, one of them a repeat visit to the OpenLayers WMS template that 8.6.2 had already patched. The templating path keeps producing findings.
View source ↗ - 3mo ago
Security release: SLD parser vulnerability
A single advisory in the SLD parser — styling input supplied per request, and therefore attacker-controlled in a public service.
View source ↗ - 3mo ago
Security release: OpenLayers template with WMS 1.3.0 requests
One advisory in the OpenLayers template under WMS 1.3.0 requests. The first of the two OpenLayers findings in this series.
View source ↗ - 4mo ago
First security release of the 8.6 series
A single advisory released three months after 8.6.0, opening the run of security-only releases that has continued since. The note does not identify the affected component.
View source ↗ - 8mo ago
The 8.6 feature release, published without visible detail
The only non-security release in the window, and the entry points at an external announcement rather than listing changes. Everything after it on this branch has been advisory-driven.
View source ↗