PYSEC-2026-841
Dashboard / Vulnerabilities / PYSEC-2026-841
PYSEC-2026-841
Summary: MapProxy vulnerable to cross-site scripting in demo service
Details: MapProxy version 1.11.1 and older are vulnerable to cross-site scripting in the demo service resulting in possible information disclosure. An incomplete fix was released in v[1.10.4](https://github.com/mapproxy/mapproxy/issues/322#issuecomment-518573169), and a complete fix was released in v[1.11.1](https://github.com/mapproxy/mapproxy/commit/436c8f489761d1b4ee22b2440b53cc96bbc28aea).
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000426, https://github.com/mapproxy/mapproxy/issues/322, https://github.com/mapproxy/mapproxy/commit/420412aad45171e05752007a0a2350c03c28dfd8, https://github.com/mapproxy/mapproxy/commit/436c8f489761d1b4ee22b2440b53cc96bbc28aea, https://github.com/mapproxy/mapproxy, https://pypi.org/project/mapproxy, https://github.com/advisories/GHSA-g4rw-82hq-8jpr
Affected packages
Package
Name: mapproxy
Purl: pkg:pypi/mapproxy
Affected ranges
Type: ECOSYSTEM
Events:
