This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Search Engines
✓ No known CVEs patched
This release patches 1 known CVE
Topics
docker
gl-styles
mapbox-gl-js
maplibre-gl-js
openmaptiles
raster-map
+4 more
tileserver
tileserver-gl
vector-tiles
wmts
Summary
AI summaryAdded ignore‑missing‑files CLI option, POST support for static maps, and native Leaflet retina raster tile support.
Full changelog
✨ Features and improvements
- Update Maplibre-Native to v6.4.1
- Remove Hillshade and Color relief workaround since it is now supported in maplibre-native (#2044) (by acalcutt)
- feat: Add ignore-missing-files cli option to avoid crashing at startup (#1896) (by andrewlaguna824)
- Add POST requests for static maps (fixes #408) (#2064) (by zstadler)
- Add Native Leaflet Retina Support for Raster Tiles (#2074) (by acalcutt)
🐞 Bug fixes
- fix: correctly handle public url in tileJSON response (#1963) (by andrewlaguna824)
- Fix regex to allow underscore in font name (#1986) (by spatialillusions)
- fix: mitigate Host header poisoning (HNP) with TILESERVER_GL_ALLOWED_… (#2032) (by LeaveerWang)
Security Fixes
- Mitigate Host header poisoning with TILESERVER_GL_ALLOWED_HOSTS and related env vars
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About TileServer GL
Vector and raster maps with GL styles. Server side rendering by Mapbox GL Native. Map tile server for Mapbox GL JS, Android, iOS, Leaflet, OpenLayers, GIS via WMTS, etc.
Related context
Beta — feedback welcome: [email protected]