A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
History

Mon, 19 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Mapnik
Mapnik mapnik
Vendors & Products Mapnik
Mapnik mapnik

Sun, 18 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Mapnik dbfile.cpp string_value heap-based overflow
Weaknesses CWE-119
CWE-122
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-01-18T10:02:07.636Z

Reserved: 2026-01-17T16:29:49.299Z

Link: CVE-2025-15537

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-18T10:15:52.103

Modified: 2026-01-18T10:15:52.103

Link: CVE-2025-15537

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-18T10:02:07Z

Links: CVE-2025-15537 - Bugzilla