CVE-2025-30145
GeoServer is an open source server that allows users to share and edit geospatial data.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerability is fixed in 2.27.0, 2.26.3, and 2.25.7. This vulnerability can be mitigated by disabling WMS dynamic styling and the Jiffle process.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- osgeo/geoserver
- Source
- security-advisories@github.com
References
- https://github.com/geoserver/geoserver/security/advisories/GHSA-gr67-pwcv-76gfThird Party Advisory
- https://github.com/geosolutions-it/jai-ext/pull/307Patch
- https://osgeo-org.atlassian.net/browse/GEOS-11778Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.