mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3. | |
| Title | mapfish-print: Remote Code Injection (RCE) in Dynamic table | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-28T14:35:29.378Z
Updated: 2026-05-28T15:26:01.990Z
Reserved: 2026-05-07T16:20:08.659Z
Link: CVE-2026-44672
Updated: 2026-05-28T15:25:54.912Z
Status : Received
Published: 2026-05-28T16:16:24.843
Modified: 2026-05-28T16:16:24.843
Link: CVE-2026-44672
No data.