← Back to all sparks
M

MapServer

DEVOPS
Velocity2.5

Platform for publishing spatial data and interactive maps

Five of MapServer's last six releases exist to fix security advisories.

geospatialogc-servicessecurity-advisoriesbranch-eolwms
Current state
Since 8.6.0 shipped in December 2025, every release on this feed has been a security release. 8.6.1 through 8.6.4 each carried one or two advisories, covering the SLD parser, the OpenLayers WMS template and PostGIS support. 8.6.5 carried six at once, spanning OGC API Features, WCS, the OpenLayers viewer, WMS GetLegendGraphic, and both MySQL and PostgreSQL JOIN handling. Every note repeats that 7.6 security support has ended and 8.4, 8.2 and 8.0 are unsupported.
Where it's heading
The advisory pattern is the story: the vulnerabilities cluster in the request-parsing and templating paths that turn user input into output, which is the oldest and most exposed part of a CGI-era mapping server. Concentrating all support on the 8.6 branch and repeatedly saying so is the project's way of forcing an upgrade it cannot otherwise compel. Feature content is not visible in this feed at all.
Prediction
The cadence suggests further 8.6.x security releases at roughly monthly intervals rather than a feature release in the near term.

Recent moves

  1. 29d ago

    Six advisories fixed across OGC API, WCS, WMS and JOIN support

    The largest security release in this window by some margin, spanning OGC API Features, WCS, the OpenLayers viewer, GetLegendGraphic and both MySQL and PostgreSQL JOIN paths. Six advisories in one release points at a coordinated audit rather than individual reports.

    View source ↗
  2. 2mo ago

    Security release: OpenLayers viewer and PostGIS advisories

    Two advisories, one of them a repeat visit to the OpenLayers WMS template that 8.6.2 had already patched. The templating path keeps producing findings.

    View source ↗
  3. 3mo ago

    Security release: SLD parser vulnerability

    A single advisory in the SLD parser — styling input supplied per request, and therefore attacker-controlled in a public service.

    View source ↗
  4. 3mo ago

    Security release: OpenLayers template with WMS 1.3.0 requests

    One advisory in the OpenLayers template under WMS 1.3.0 requests. The first of the two OpenLayers findings in this series.

    View source ↗
  5. 4mo ago

    First security release of the 8.6 series

    A single advisory released three months after 8.6.0, opening the run of security-only releases that has continued since. The note does not identify the affected component.

    View source ↗
  6. 8mo ago

    The 8.6 feature release, published without visible detail

    The only non-security release in the window, and the entry points at an external announcement rather than listing changes. Everything after it on this branch has been advisory-driven.

    View source ↗