Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55848— mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types

Quick assessment

Affected
mapfish mapfish-print
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

mapfish-print 是 MapFish 项目中用于打印模板化制图地图的组件。在版本 3.28.30、3.30.32、3.31.24、3.33.16 和 4.0.5 之前,MapFish Print 在处理 /api/print3/print 端点的请求时,会接受攻击者可控的 GML 图层 URL,并获取由 解析的 XML,但解析过程中未禁用外部实体和外部 DTD。远程 XML 文档和 DTD 可以扩展本地文件实体,其结果可通过 GML 解析及错误路径泄露出来。这允许未认证的攻击者读取诸如操作系统账户数据、K

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55848

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types
Source: CVE Program / CVE List V5
Vulnerability Description
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/print/map/geotools/GmlLayer.java without disabling external entities and external DTDs. A remote XML document and DTD can expand a local file entity, and the resulting content can be exposed through the GML parsing and error path. This allows unauthenticated attackers to read files such as operating-system account data, Kubernetes service-account tokens, and certificates. Replacing the file entity target with an internal HTTP endpoint also permits server-side request forgery. This issue is fixed in versions 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mapfish mapfish-print >= 3.0.0, < 3.28.30 -
mapfish org.mapfish.print.print-lib >= 3.0.0, < 3.28.30 -
mapfish org.mapfish.print.print-servlet >= 3.0.0, < 3.28.30 -

II. Public POCs for CVE-2026-55848

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55848

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55848 (12)

Vendor Advisories for CVE-2026-55848 (1)

Vendor Pages for CVE-2026-55848 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55848

No comments yet


Leave a comment