{"id":"CVE-2025-30145","aliases":["GHSA-gr67-pwcv-76gf"],"url":"https://o3.security/vulnerability/CVE-2025-30145","summary":"GeoServer has an Infinite Loop Vulnerability in Jiffle process","details":"### Summary\nMalicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service.\n\n### Details\nThe Jiffle language supports multiple loop constructs that will cause its code block to be continuously executed until a certain condition is met. The Jiffle runtime should be updated to throw an exception if the script exceeds a certain number of loop iterations.\n\n### Impact\nThis vulnerability allows attackers to conduct denial-of-service attacks.\n\n### Mitigation\nThis vulnerability can be mitigated by disabling WMS dynamic styling (see [WMS Settings](https://docs.geoserver.org/latest/en/user/services/wms/webadmin.html#disabling-usage-of-dynamic-styling-in-getmap-getfeatureinfo-and-getlegendgraphic-requests)).\nIf the WPS extension is installed, the Jiffle process must also be disabled to mitigate this vulnerability (see [WPS Settings](https://docs.geoserver.org/latest/en/user/services/wps/security.html#input-limits))\n\n### References\nhttps://github.com/geosolutions-it/jai-ext/pull/307\nhttps://osgeo-org.atlassian.net/browse/GEOS-11778","published":"2025-06-10T14:58:48.408Z","modified":"2026-08-12T03:51:15.257058615Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00449,"percentile":0.37147,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.geoserver.web:gs-web-app","fixedVersion":"2.26.3"},{"ecosystem":"Maven","name":"org.geoserver:gs-wms","fixedVersion":"2.26.3"},{"ecosystem":"Maven","name":"org.geoserver.extension:gs-wps-core","fixedVersion":"2.26.3"},{"ecosystem":"Maven","name":"org.geoserver.web:gs-web-app","fixedVersion":"2.25.7"},{"ecosystem":"Maven","name":"org.geoserver:gs-wms","fixedVersion":"2.25.7"},{"ecosystem":"Maven","name":"org.geoserver.extension:gs-wps-core","fixedVersion":"2.25.7"}],"fix":{"url":"https://github.com/geosolutions-it/jai-ext/pull/307","label":"geosolutions-it/jai-ext#307"},"references":[{"type":"WEB","url":"https://osgeo-org.atlassian.net/browse/GEOS-11778"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30145.json"},{"type":"ADVISORY","url":"https://github.com/geoserver/geoserver/security/advisories/GHSA-gr67-pwcv-76gf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30145"},{"type":"FIX","url":"https://github.com/geosolutions-it/jai-ext/pull/307"},{"type":"PACKAGE","url":"https://github.com/geoserver/geoserver"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.257058615Z"}}