Executive brief
MapFish Print is a tool used to generate high-quality map documents from web-based mapping applications. A critical security flaw allows an unauthenticated attacker to remotely execute arbitrary code on the server by exploiting the dynamic table feature. This could lead to a complete system takeover, unauthorized access to sensitive geographic data, and disruption of mapping services.
Technical details
A remote code injection vulnerability (CWE-94) exists in MapFish Print's dynamic table component. The root cause is improper neutralization of externally-influenced input used to construct code segments within the printing engine. An unauthenticated attacker can exploit this over the network by submitting a specially crafted request to the print service. Successful exploitation allows for arbitrary code execution with the privileges of the application process. Patches have been released across multiple version branches, including 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.
Affected products
- MapFish mapfish-print-lib >= 3.23.0, < 3.28.28; >= 3.29.0, < 3.30.30; >= 3.31.0, < 3.31.22; >= 3.32.0, < 3.33.14; >= 3.34.0, < 4.0.3
- MapFish mapfish-print-servlet >= 3.23.0, < 3.28.28; >= 3.29.0, < 3.30.30; >= 3.31.0, < 3.31.22; >= 3.32.0, < 3.33.14; >= 3.34.0, < 4.0.3
- Camptocamp mapfish_print (Docker) >= 3.23.0, < 3.28.28; >= 3.29.0, < 3.30.30; >= 3.31.0, < 3.31.22; >= 3.32.0, < 3.33.14; >= 3.34.0, < 4.0.3
Timeline
- 2026-05-08: disclosed
- 2026-05-13: advisory: GitHub Advisory published
- 2026-05-28: advisory: NVD published