MapServer
Platform for publishing spatial data and interactive maps
MapServer 8.6.x is in pure security-patch maintenance mode, fixing OGC protocol vulnerabilities on a regular cadence.
◆Recent moves
- 9d ago
MapServer 8.6.6: six-advisory security release
8.6.6 addresses six security advisories spanning WCS 2.0, CGI/FastCGI with SMOOTHSIA, WMS filter handling, WMS with interpolation layers, FlatGeobuf support, and WMS error image handling. The breadth of affected components in a single release makes this the most significant security event in recent MapServer history.
View source ↗ - 2mo ago
MapServer 8.6.5: six-advisory security release
8.6.5 patches six advisories across OGCAPI Features, WCS, OpenLayers/WMS integration, WMS GetLegendGraphic, MySQL JOIN, and PostgreSQL JOIN. A broad security sweep across multiple data-access and rendering pathways.
View source ↗ - 3mo ago
MapServer 8.6.4
8.6.4 patches two advisories: an OpenLayers viewer with WMS vulnerability and a PostGIS support issue. A smaller security release compared to 8.6.5.
View source ↗ - 4mo ago
MapServer 8.6.3
8.6.3 fixes a vulnerability in the SLD (Styled Layer Descriptor) parser—a format widely used for defining WMS rendering rules. Single-advisory security patch.
View source ↗ - 4mo ago
MapServer 8.6.2
8.6.2 patches a vulnerability in the OpenLayers template with WMS 1.3.0 requests. Single-advisory security patch.
View source ↗ - 5mo ago
MapServer 8.6.1
8.6.1 is a security release with one advisory. Combined with 8.6.2–8.6.6, this confirms MapServer's 8.6.x line is receiving regular security-only maintenance, with no feature development visible across this span.
View source ↗