GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerability is fixed in 2.27.0, 2.26.3, and 2.25.7. This vulnerability can be mitigated by disabling WMS dynamic styling and the Jiffle process.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerability is fixed in 2.27.0, 2.26.3, and 2.25.7. This vulnerability can be mitigated by disabling WMS dynamic styling and the Jiffle process. | |
Title | GeoServer has an Infinite Loop Vulnerability in Jiffle process | |
Weaknesses | CWE-835 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-10T14:58:48.408Z
Updated: 2025-06-10T15:16:31.100Z
Reserved: 2025-03-17T12:41:42.564Z
Link: CVE-2025-30145

Updated: 2025-06-10T15:16:19.470Z

Status : Awaiting Analysis
Published: 2025-06-10T15:15:24.070
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-30145

No data.