Denial of Service Vulnerability in GeoServer Affecting Geospatial Data Management
CVE-2025-30145

7.5HIGH

Key Information:

Vendor

Geoserver

Status
Vendor
CVE Published:
10 June 2025

What is CVE-2025-30145?

GeoServer, an open-source server designed for sharing and editing geospatial data, is prone to a vulnerability that allows the execution of malicious Jiffle scripts. These scripts can be triggered through either WMS dynamic styles or WPS processes, potentially leading to an infinite loop scenario. Consequently, this can cause denial of service, disrupting normal operations. Users are advised to upgrade to fixed versions 2.27.0, 2.26.3, or 2.25.7 to mitigate this risk. Disabling WMS dynamic styling and the Jiffle process is also recommended to enhance security.

Affected Version(s)

geoserver >= 2.26.0, < 2.26.3 < 2.26.0, 2.26.3

geoserver < 2.25.7 < 2.25.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30145 : Denial of Service Vulnerability in GeoServer Affecting Geospatial Data Management