Denial of Service Vulnerability in GeoServer Affecting Geospatial Data Management
CVE-2025-30145
7.5HIGH
What is CVE-2025-30145?
GeoServer, an open-source server designed for sharing and editing geospatial data, is prone to a vulnerability that allows the execution of malicious Jiffle scripts. These scripts can be triggered through either WMS dynamic styles or WPS processes, potentially leading to an infinite loop scenario. Consequently, this can cause denial of service, disrupting normal operations. Users are advised to upgrade to fixed versions 2.27.0, 2.26.3, or 2.25.7 to mitigate this risk. Disabling WMS dynamic styling and the Jiffle process is also recommended to enhance security.
Affected Version(s)
geoserver >= 2.26.0, < 2.26.3 < 2.26.0, 2.26.3
geoserver < 2.25.7 < 2.25.7