{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-55848/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-55848"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["print-lib (3.0.0-3.28.29, 3.29.0-3.30.31, 3.32.0-3.33.15, 3.34.0-4.0.4)","print-servlet (3.0.0-3.28.29, 3.29.0-3.30.31, 3.31.0-3.31.23, 3.32.0-3.33.15, 3.34.0-4.0.4)"],"_cs_severities":["high"],"_cs_tags":["xxe","cve-2026-55848","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["MapFish"],"content_html":"\u003cp\u003eMapFish Print, a Java-based web application for generating printable reports, contains an XML External Entity (XXE) vulnerability identified as CVE-2026-55848. The issue originates from the way the print service processes GML layers. By submitting a JSON payload to the \u003ccode\u003e/api/print3/print/mapviewer/buildreport.pdf\u003c/code\u003e endpoint with a manipulated GML layer URL, an attacker can point the application to a remote, malicious DTD file.\u003c/p\u003e\n\u003cp\u003eWhen processed, this configuration triggers the XXE, which can be leveraged to exfiltrate local files from the server, perform directory listing, or initiate SSRF attacks against internal network resources. The vulnerability affects multiple versions of the \u003ccode\u003eprint-lib\u003c/code\u003e and \u003ccode\u003eprint-servlet\u003c/code\u003e components within the 3.x and 4.x branches. This impact is significant for organizations deploying MapFish Print in cloud environments, as it may lead to the exposure of Kubernetes service account tokens or other sensitive system credentials.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker stands up a remote server hosting a malicious PHP script (xxe.php) and an associated DTD file (evil.dtd).\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a JSON request for the MapFish Print \u003ccode\u003ebuildreport.pdf\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe JSON request includes a \u003ccode\u003elayers\u003c/code\u003e object with the \u003ccode\u003etype\u003c/code\u003e set to \u003ccode\u003egml\u003c/code\u003e and a \u003ccode\u003eurl\u003c/code\u003e pointing to the attacker-controlled \u003ccode\u003exxe.php\u003c/code\u003e script with a file path parameter (e.g., \u003ccode\u003e/etc/passwd\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe MapFish Print server initiates an HTTP request to the attacker-controlled \u003ccode\u003exxe.php\u003c/code\u003e server to retrieve the XML configuration.\u003c/li\u003e\n\u003cli\u003eThe attacker's server responds with an XML document containing the malicious DTD and the defined entity, which triggers the file read on the MapFish server.\u003c/li\u003e\n\u003cli\u003eThe MapFish server attempts to load the file referenced by the entity, and the error processing mechanism (specifically 404 handler) returns the content of the target file in the response body.\u003c/li\u003e\n\u003cli\u003eThe attacker receives the sensitive file contents directly in the HTTP response from the MapFish Print service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized disclosure of local server files, including sensitive configuration files and credentials. Furthermore, the vulnerability supports SSRF, enabling attackers to interact with internal infrastructure, potentially bypassing network segmentation or accessing metadata services in cloud environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade MapFish Print to the latest version (v4.0.5 or higher) to remediate CVE-2026-55848.\u003c/li\u003e\n\u003cli\u003eImplement an egress filtering policy on all MapFish Print servers to restrict outbound HTTP/HTTPS connections, preventing the application from fetching untrusted remote DTDs.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to inspect JSON payloads sent to the print API for anomalous GML layer URLs, specifically looking for external domains or unusual URI parameters.\u003c/li\u003e\n\u003cli\u003eReview server logs for anomalous outbound HTTP requests originating from the MapFish Print application process.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T03:13:43Z","date_published":"2026-08-29T03:13:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mapfish-xxe/","summary":"MapFish Print is susceptible to an XML External Entity (XXE) injection vulnerability via the GML layer processing feature, allowing attackers to perform arbitrary file reads or Server-Side Request Forgery (SSRF).","title":"XXE Vulnerability in MapFish Print","url":"https://feed.craftedsignal.io/briefs/2026-08-mapfish-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-55848","version":"https://jsonfeed.org/version/1.1"}