← Volver al buscador de CVEs

CVE-2026-42351

pygeoapi

Descripción

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi-s STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in configuration. This issue has been patched in version 0.23.3.

CVSS 7.5EPSS 0.51%Riesgo 0.78
Ver fuente
Publicación
2026-05-08 23:16:38
Versiones afectadas
>=0.23.0,<0.23.3
Tipo
Package
Última modificación
2026-07-24 21:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N