org.hibernate:hibernate-validator
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.hibernate:hibernate-validatorpage 1 of 1
- CVE-2014-3558MEDIUMCVSS v2 5.0EG 5.0fixed in 4.2.1, 4.3.2 or 5.1.2, by version range2014-09-30
vulnerable: 5.0.0.Final ... 5.1.1.Final (9 versions)
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted…
- CVE-2017-7536HIGHCVSS 7.0EG 7.0fixed in 5.2.5.Final, 5.3.6.Final or 5.4.2.Final, by version range2018-01-10
vulnerable: 5.4.0.Final, 5.4.1.Final
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a pote…
- CVE-2019-10219MEDIUMCVSS 6.1EG 6.1fixed in 6.1.0.Alpha6 or 6.0.18.Final, by version range2019-11-08
vulnerable: 6.0.0.Alpha1 ... 6.0.9.Final (25 versions)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS att…
- CVE-2020-10693MEDIUMCVSS 5.3EG 5.3fixed in 6.1.5.Final or 6.0.20.Final, by version range2020-05-06
vulnerable: 3.0.0.GA ... 6.0.9.Final (99 versions)
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping…
- CVE-2023-1932MEDIUMCVSS 6.1EG 6.1fixed in 6.2.0.Final2024-11-07
vulnerable: 3.0.0.GA ... 6.2.0.CR1 (118 versions)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may ren…
- CVE-2025-35036HIGHCVSS 7.3EG 7.3fixed in 6.2.0.CR1 or 7.0.0.CR1, by version range2025-06-03
vulnerable: 7.0.0.Alpha1 ... 7.0.0.Alpha6 (6 versions)
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive informati…
Check whether org.hibernate:hibernate-validator is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.hibernate:hibernate-validator CVEs against the assets you own.
Book a Demo →