← Back to all sparks
M

MapServer

DEVOPS
Velocity2.5

Platform for publishing spatial data and interactive maps

MapServer 8.6.x is in pure security-patch maintenance mode, fixing OGC protocol vulnerabilities on a regular cadence.

geospatialopen-sourceogcsecuritywmswcs
Current state
MapServer is a mature open-source geospatial web server implementing OGC standards (WMS, WCS, WFS, OGCAPI). Every recent release on the 8.6.x branch is a security fix targeting vulnerabilities in specific protocol handlers: WCS 2.0, CGI/FastCGI with SMOOTHSIA, WMS filter handling, FlatGeobuf support, and PostGIS/MySQL JOIN support have all received advisories in recent months. The team consistently urges users on 7.6.x (end-of-life) or branches 8.0–8.4 (unsupported) to upgrade.
Where it's heading
MapServer's release pattern is stable maintenance, not active feature development. No new capabilities are visible in the last 10 entries—only security patches and an ongoing migration pressure campaign toward 8.6.x. The project remains essential infrastructure for organizations running OGC-compliant geospatial services, but it's not expanding its capability surface. Without a new major or minor version in progress, the near-term horizon is continued security hardening on 8.6.x.
Prediction
Security releases will continue at roughly the current 5–8 week cadence. A new feature release is not predictable from these entries—whether one is in development would require looking at the upstream MapServer development mailing list or roadmap.

Recent moves

  1. 9d ago

    MapServer 8.6.6: six-advisory security release

    8.6.6 addresses six security advisories spanning WCS 2.0, CGI/FastCGI with SMOOTHSIA, WMS filter handling, WMS with interpolation layers, FlatGeobuf support, and WMS error image handling. The breadth of affected components in a single release makes this the most significant security event in recent MapServer history.

    View source ↗
  2. 2mo ago

    MapServer 8.6.5: six-advisory security release

    8.6.5 patches six advisories across OGCAPI Features, WCS, OpenLayers/WMS integration, WMS GetLegendGraphic, MySQL JOIN, and PostgreSQL JOIN. A broad security sweep across multiple data-access and rendering pathways.

    View source ↗
  3. 3mo ago

    MapServer 8.6.4

    8.6.4 patches two advisories: an OpenLayers viewer with WMS vulnerability and a PostGIS support issue. A smaller security release compared to 8.6.5.

    View source ↗
  4. 4mo ago

    MapServer 8.6.3

    8.6.3 fixes a vulnerability in the SLD (Styled Layer Descriptor) parser—a format widely used for defining WMS rendering rules. Single-advisory security patch.

    View source ↗
  5. 4mo ago

    MapServer 8.6.2

    8.6.2 patches a vulnerability in the OpenLayers template with WMS 1.3.0 requests. Single-advisory security patch.

    View source ↗
  6. 5mo ago

    MapServer 8.6.1

    8.6.1 is a security release with one advisory. Combined with 8.6.2–8.6.6, this confirms MapServer's 8.6.x line is receiving regular security-only maintenance, with no feature development visible across this span.

    View source ↗