CVE-2026-55848: MapFish Print has XXE that allows reading arbitrary files of certain types
XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs.
https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507
References
- github.com/advisories/GHSA-5v29-34h8-v68r
- github.com/mapfish/mapfish-print/commit/13beae7a7f970fc3526c1f7ca5db817d8d51fbec
- github.com/mapfish/mapfish-print/commit/23a96e7baa15077bdb0e5fc5a72b18da23af9121
- github.com/mapfish/mapfish-print/commit/3525e8150fcb5f40095930ccf7aec0d8ce92bbcb
- github.com/mapfish/mapfish-print/commit/56c47d3bf70d8428916dea8ed7005518ad07dc7d
- github.com/mapfish/mapfish-print/commit/a55a24873db5f19b37abac7d59144dc86406c236
- github.com/mapfish/mapfish-print/commit/d13911ac6e0509444d64e74830f10b14e4dcfdf1
- github.com/mapfish/mapfish-print/pull/4212
- github.com/mapfish/mapfish-print/pull/4215
- github.com/mapfish/mapfish-print/pull/4216
- github.com/mapfish/mapfish-print/pull/4217
- github.com/mapfish/mapfish-print/pull/4219
- github.com/mapfish/mapfish-print/pull/4221
- github.com/mapfish/mapfish-print/releases/tag/3.28.30
- github.com/mapfish/mapfish-print/releases/tag/3.30.32
- github.com/mapfish/mapfish-print/releases/tag/3.31.24
- github.com/mapfish/mapfish-print/releases/tag/4.0.5
- github.com/mapfish/mapfish-print/security/advisories/GHSA-5v29-34h8-v68r
- nvd.nist.gov/vuln/detail/CVE-2026-55848
Code Behaviors & Features
Detect and mitigate CVE-2026-55848 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →