Description
A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Timeline
| 2026-02-05: | Advisory disclosed |
| 2026-02-05: | VulDB entry created |
| 2026-02-08: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.344502 (VDB-344502 | Mapnik value.cpp operator divide by zero)
vuldb.com/?ctiid.344502 (VDB-344502 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.743386 (Submit #743386 | mapnik Mapnik v4.2.0 and master branch Divide By Zero)
github.com/mapnik/mapnik/issues/4545
github.com/oneafter/1219/blob/main/repro
github.com/mapnik/mapnik/