THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5v29-34h8-v68r (high) — MapFish Print has XXE that allows reading arbitrary files of certain types

[GHSA] GHSA-5v29-34h8-v68r (high) — MapFish Print has XXE that allows reading arbitrary files of certain types

highgithub_advisoriesPublished 2026-08-28

GHSA-5v29-34h8-v68r Severity: high CVE: CVE-2026-55848

MapFish Print has XXE that allows reading arbitrary files of certain types

### Summary XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs.

https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507

### Details To trigger the XXE it is required to host a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5v29-34h8-v68r