---
id: CVE-2026-50126
title: >-
  Adaguc-server is an open source geographical information system to visualize,
  combine, compare and share real-time meteorological, climatological and remote
  sensing data via OGC standards
summary: >-
  Adaguc-server is an open source geographical information system to visualize,
  combine, compare and share real-time meteorological, climatological and remote
  sensing data via OGC standards. Versions prior to 7.2.2 crash with a
  memory-safe…
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
  - CWE-476
published: '2026-08-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50126'
references:
  - url: >-
      https://github.com/KNMI/adaguc-server/commit/30dffde1a1776b994d60026f41ca620f7cad72e9
    label: security-advisories@github.com
  - url: 'https://github.com/KNMI/adaguc-server/pull/710'
    label: security-advisories@github.com
  - url: 'https://github.com/KNMI/adaguc-server/releases/tag/7.2.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/KNMI/adaguc-server/security/advisories/GHSA-mwgv-59vv-rp2m
    label: security-advisories@github.com
  - url: >-
      https://github.com/KNMI/adaguc-server/security/advisories/GHSA-mwgv-59vv-rp2m
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06417
ingestedAt: '2026-09-18T20:51:25.632Z'
---

## Overview

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document whose geometry contains a malformed coordinate. The coordinate parser in `adagucserverEC/CConvertGeoJSON.cpp` indexes `pt.u.array.values[0]` and `pt.u.array.values[1]` and uses `polygon.u.array.length` as a loop bound without first validating the JSON node type or the coordinate length. A coordinate that is an empty array, a one-element array, a scalar, or `null` leads to an out-of-bounds heap read or a NULL pointer dereference. The same unchecked pattern is present in four geometry branches: `Polygon`, `LineString`, `MultiLineString` and `MultiPolygon`. The vulnerable parser runs whenever the server processes a local GeoJSON file, either a configured GeoJSON dataset or a GeoJSON file exposed through the `AutoResource` feature and requested by an unauthenticated WMS request. A crafted GeoJSON file reliably crashes the backend process that handles that request. Version 7.2.2 patches the vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
