CVE-2026-27818: Terria Terriajs-Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.

Affected products

  • Terria Terriajs-Server: before 4.0.3 (fixed in 4.0.3)

Published 2026-02-26. Last modified 2026-06-17.