CVE-2026-55848
high
CVSS v3
8.6
CVSS v4 NEW
—
VIR risk
8.6
Description
MapFish Print has XXE that allows reading arbitrary files of certain types
Predictions
Exploit likelihood
91%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.mapfish.print:print-lib | >=3.0.0,<3.28.30 | 3.28.30 |
| Maven | org.mapfish:print.print-servlet | >=3.0.0,<3.28.30 | 3.28.30 |
| Maven | org.mapfish.print:print-lib | >=3.29.0,<3.30.32 | 3.30.32 |
| Maven | org.mapfish.print:print-servlet | >=3.29.0,<3.30.32 | 3.30.32 |
| Maven | org.mapfish.print:print-servlet | >=3.31.0,<3.31.24 | 3.31.24 |
| Maven | org.mapfish.print:print-lib | >=3.32.0,<3.33.16 | 3.33.16 |
| Maven | org.mapfish.print:print-servlet | >=3.32.0,<3.33.16 | 3.33.16 |
| Maven | org.mapfish.print:print-lib | >=3.34.0,<4.0.5 | 4.0.5 |
| Maven | org.mapfish.print:print-servlet | >=3.34.0,<4.0.5 | 4.0.5 |
References
- https://github.com/mapfish/mapfish-print/commit/13beae7a7f970fc3526c1f7ca5db817d8d51fbec
- https://github.com/mapfish/mapfish-print/commit/23a96e7baa15077bdb0e5fc5a72b18da23af9121
- https://github.com/mapfish/mapfish-print/commit/3525e8150fcb5f40095930ccf7aec0d8ce92bbcb
- https://github.com/mapfish/mapfish-print/commit/56c47d3bf70d8428916dea8ed7005518ad07dc7d
- https://github.com/mapfish/mapfish-print/commit/a55a24873db5f19b37abac7d59144dc86406c236
- https://github.com/mapfish/mapfish-print/commit/d13911ac6e0509444d64e74830f10b14e4dcfdf1
- https://github.com/mapfish/mapfish-print/pull/4212
- https://github.com/mapfish/mapfish-print/pull/4215
- https://github.com/mapfish/mapfish-print/pull/4216
- https://github.com/mapfish/mapfish-print/pull/4217
- https://github.com/mapfish/mapfish-print/pull/4219
- https://github.com/mapfish/mapfish-print/pull/4221
- https://github.com/mapfish/mapfish-print/releases/tag/3.28.30
- https://github.com/mapfish/mapfish-print/releases/tag/3.30.32
- https://github.com/mapfish/mapfish-print/releases/tag/3.31.24
- https://github.com/mapfish/mapfish-print/releases/tag/4.0.5
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-5v29-34h8-v68r
- https://github.com/mapfish/mapfish-print
CWEs
CWE-611
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.