← Voltar à pesquisa de CVEs

CVE-2026-42351

pygeoapi

Descrição

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi-s STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in configuration. This issue has been patched in version 0.23.3.

CVSS 7.5EPSS 0.51%Risco 0.78
Ver fonte
Publicação
2026-05-08 23:16:38
Versões afetadas
>=0.23.0,<0.23.3
Tipo
Package
Última alteração
2026-07-24 21:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N