CVE-2026-42351Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in configuration. This issue has been patched in version 0.23.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-01: 1Mentions · 2026-05-09: 2Mentions · 2026-05-29: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-29: 205-0105-0905-29
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-011
Disclosure1
2026-05-092
Disclosure2
2026-05-292
Disclosure2
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42351 · 7.5 → 0.23.0 TL;DR Two critical vulnerabilities in pygeoapi 0.23.0–0.23.2 (a widely-deployed OGC-compliant geospatial data API) allow unauthenticated attackers to read arbitrary files via path traversal and access internal services via server-side request…

    Post summary

    The post announces two critical vulnerabilities in pygeoapi 0.23.0–0.23.2 that enable unauthenticated attackers to read arbitrary files and access internal services through server‑side requests.

    1000039
    231 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: CVE-2026-42351 (CVSS 7.5 - Path Traversal): The vulnerability exists in pygeoapi's STAC FileSystemProvider plugin. The getdatapath() function constructs file system paths via unsanitized string concatenation. An unauthenticated…

    Post summary

    The passage announces a Path Traversal vulnerability (CVE‑2026‑42351) in pygeoapi's STAC FileSystemProvider plugin, providing technical details but no proof‑of‑concept, exploit code, or mitigation information.

    1000042
    231 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42351 pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-42351

    Post summary

    The text announces CVE-2026-42351, a raw string path concatenation flaw in pygeoapi versions 0.23.0‑0.23.2, without mentioning patches, PoCs, or active exploitation.

    0000070
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42351 Path Traversal Directory Exposure in pygeoapi STAC FileSystemProvider Versions 0.23.0-0.23.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42351

    Post summary

    The message announces CVE‑2026‑42351, detailing a path traversal flaw in specific pygeoapi versions, with no PoC, exploit code, or patch information provided.

    0000045
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pygeoapi, Path Traversal, #CVE-2026-42351 (Critical) https://dailycve.com/pygeoapi-path-traversal-cve-2026-42351-critical/

    Post summary

    The post announces a critical path‑traversal vulnerability in pygeoapi (CVE‑2026‑42351) and links to a dailyCVE article, without providing exploitation code, evidence of active attacks, or patch information.

    0000028
    192 followersView on X

Explore more