CVE-2025-15537

A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/mapnik/mapnik/
https://github.com/mapnik/mapnik/issues/4543 Exploit Issue Tracking Vendor Advisory
https://github.com/oneafter/1218/blob/main/repro Product
https://vuldb.com/?ctiid.341709 Permissions Required VDB Entry
https://vuldb.com/?id.341709 Third Party Advisory VDB Entry
https://vuldb.com/?submit.733348 Exploit Third Party Advisory VDB Entry
https://github.com/mapnik/mapnik/issues/4543 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mapnik:mapnik:*:*:*:*:*:*:*:*

History

23 Feb 2026, 09:16

Type Values Removed Values Added
References
  • () https://github.com/mapnik/mapnik/ -
References () https://github.com/mapnik/mapnik/issues/4543 - Exploit, Vendor Advisory, Issue Tracking () https://github.com/mapnik/mapnik/issues/4543 - Exploit, Issue Tracking, Vendor Advisory

06 Feb 2026, 20:31

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:mapnik:mapnik:*:*:*:*:*:*:*:*
First Time Mapnik
Mapnik mapnik
References () https://github.com/mapnik/mapnik/issues/4543 - () https://github.com/mapnik/mapnik/issues/4543 - Exploit, Vendor Advisory, Issue Tracking
References () https://github.com/oneafter/1218/blob/main/repro - () https://github.com/oneafter/1218/blob/main/repro - Product
References () https://vuldb.com/?ctiid.341709 - () https://vuldb.com/?ctiid.341709 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.341709 - () https://vuldb.com/?id.341709 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.733348 - () https://vuldb.com/?submit.733348 - Exploit, Third Party Advisory, VDB Entry

20 Jan 2026, 17:15

Type Values Removed Values Added
References () https://github.com/mapnik/mapnik/issues/4543 - () https://github.com/mapnik/mapnik/issues/4543 -

18 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-18 10:15

Updated : 2026-02-23 09:16


NVD link : CVE-2025-15537

Mitre link : CVE-2025-15537

CVE.ORG link : CVE-2025-15537


JSON object : View

Products Affected

mapnik

  • mapnik
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write