PT-2025-23663 · Hibernate+5 · Hibernate Validator+4

Published

2025-06-03

·

Updated

2025-07-01

·

CVE-2025-35036

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE-2025-35036 Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expres… https://t.co/002YgA2hEa

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-35036
GHSA-7V6M-28JR-RG84
RHSA-2025:10924
RHSA-2025:10925
RHSA-2025:10926

Affected Products

Hibernate Validator
Libhibernate-Validator-Java
Libhibernate-Validator4-Java
Org.Hibernate.Validator:Hibernate-Validator
Org.Hibernate:Hibernate-Validator