Mapnik is a geospatial rendering library employed across mapping and visualization applications, with a focused but strategically important role in processing cartographic data and vector graphics. Its vulnerability surface centers on memory-handling issues endemic to native rendering code, including divide-by-zero conditions, heap-based buffer overflows, and out-of-bounds writes, alongside improper resource shutdown and boundary violations that arise in the parsing and rendering pipeline. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mapnik over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15537MEDIUM A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such ma | Jan 18, 2026 | 5.5 | 23 | NO | NO |
CVE-2025-15564MEDIUM A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads t | Feb 7, 2026 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapnik.
Media articles that mention a CVE ID that affects a product developed by Mapnik — matched by CVE ID, not by vendor name.