CVE 7.5 HIGH

pygeoapi: Path Traversal in STAC FileSystemProvider_CVE-2026-42351

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in configuration. This issue has been patched in version 0.23.3.

Basic Information

ID CVE-2026-42351
Source GitHub_M
Published May 8, 2026 at 22:31

Affected Product

Vendor geopython
Product pygeoapi
Version >= 0.23.0, < 0.23.3
Affected Versions geopython pygeoapi >= 0.23.0, < 0.23.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.