Mapfish Print: Remote Code Injection (RCE) in Dynamic table
Critical severity
GitHub Reviewed
Published
May 8, 2026
in
mapfish/mapfish-print
•
Updated Jun 9, 2026
Package
Affected versions
>= 3.23.0, < 3.28.28
>= 3.29.0, < 3.30.30
>= 3.31.0, < 3.31.21
>= 3.32.0, < 3.33.14
>= 3.34.0, < 4.0.3
Patched versions
3.28.28
3.30.30
3.31.21
3.33.14
4.0.3
>= 3.23.0, < 3.28.28
>= 3.29.0, < 3.30.30
>= 3.31.0, < 3.31.21
>= 3.32.0, < 3.33.14
>= 3.34.0, < 4.0.3
3.28.28
3.30.30
3.31.21
3.33.14
4.0.3
Description
Published to the GitHub Advisory Database
May 13, 2026
Reviewed
May 13, 2026
Published by the National Vulnerability Database
May 28, 2026
Last updated
Jun 9, 2026
Impact
The attacker can execute arbitrary code without being authenticated
Mitigation
Upgrade to a patched version (please check affected/patched version matrix)
Credits
Bug Bounty of Canton du Jura
References