VYPR

Maven package

org.hibernate.validator/hibernate-validator

pkg:maven/org.hibernate.validator/hibernate-validator

Vulnerabilities (4)

  • CVE-2025-35036Jun 3, 2025
    affected < 6.2.0.CR1fixed 6.2.0.CR1

    Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibern

  • CVE-2023-1932Nov 7, 2024
    affected < 6.2.0.Finalfixed 6.2.0.Final

    A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML inject

  • CVE-2020-10693May 6, 2020
    affected >= 6.1.0.Final, < 6.1.5.Finalfixed 6.1.5.Final

    A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may

  • CVE-2019-10219Nov 8, 2019
    affected >= 6.1.0.Alpha1, < 6.1.0.Alpha6fixed 6.1.0.Alpha6

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.