PT-2025-23663 · Debian · Debian

CVE-2025-35036

·

Published

2025-06-03

·

Updated

2025-07-01

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Hibernate Validator versions prior to 6.2.0 Hibernate Validator versions prior to 7.0.0
Description Depending on the configuration and usage, the software may interpolate user-supplied input within a constraint violation message using Expression Language (EL), a mechanism that allows for the dynamic evaluation of expressions within a string.
Recommendations Update Hibernate Validator to version 6.2.0 or later. Update Hibernate Validator to version 7.0.0 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-35036
GHSA-7V6M-28JR-RG84
RHSA-2025:10924
RHSA-2025:10925
RHSA-2025:10926

Affected Products

Debian