Denial of Service Vulnerability in GeoServer Affecting Geospatial Data Management
CVE-2025-30145
What is CVE-2025-30145?
GeoServer, an open-source server designed for sharing and editing geospatial data, is prone to a vulnerability that allows the execution of malicious Jiffle scripts. These scripts can be triggered through either WMS dynamic styles or WPS processes, potentially leading to an infinite loop scenario. Consequently, this can cause denial of service, disrupting normal operations. Users are advised to upgrade to fixed versions 2.27.0, 2.26.3, or 2.25.7 to mitigate this risk. Disabling WMS dynamic styling and the Jiffle process is also recommended to enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
geoserver >= 2.26.0, < 2.26.3 < 2.26.0, 2.26.3
geoserver < 2.25.7 < 2.25.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
