CVE Explorer
CVE-2026-42351
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pygeoapi","vendor":"geopython","versions":[{"status":"affected","version":">= 0.23.0, < 0.23.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/geopython/pygeoapi/commit/bf25b8695edbdd5476eeffc102b633d1d3e45f52","tags":["x_refsource_MISC"],"url":"https://github.com/geopython/pygeoapi/commit/bf25b8695edbdd5476eeffc102b633d1d3e45f52"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/references/1
{"name":"https://github.com/geopython/pygeoapi/releases/tag/0.23.3","tags":["x_refsource_MISC"],"url":"https://github.com/geopython/pygeoapi/releases/tag/0.23.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/references/2
{"name":"https://github.com/geopython/pygeoapi/security/advisories/GHSA-f6pr-83pg-ghh6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/geopython/pygeoapi/security/advisories/GHSA-f6pr-83pg-ghh6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:154ad68c1b47491cdb328ae50e74d2bba4c44d853855fae74598e0cbe0a0dde0 · sha256:1811936214823dfd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.