Infinite loop in geoserver - CVE-2025-30145
Published: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in the Jiffle process when executing malicious Jiffle scripts through WMS dynamic styles or as a WPS process. A remote attacker can submit a specially crafted Jiffle script to cause a denial of service.