CVE-2025-35036
published 2025-06-03CVE-2025-35036: Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with…
PriorityP345high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.65%
46.8th percentile
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libhibernate-validator-java | — | — |
| debian | libhibernate-validator4-java | — | — |
| redhat | hibernate_validator | < 6.2.0 | 6.2.0 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa8.8HIGH
osv8.8HIGH
vulncheck6.9MEDIUM
cisa6.9MEDIUM
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Hibernate Validator up to 6.1.x Expression Language code injection (EUVD-2025-16774 / Nessus ID 242091)
vuldb·2026-07-03·CVSS 7.3
CVE-2025-35036 [HIGH] Hibernate Validator up to 6.1.x Expression Language code injection (EUVD-2025-16774 / Nessus ID 242091)
A vulnerability labeled as critical has been found in Hibernate Validator up to 6.1.x. The affected element is an unknown function of the component Expression Language Handler. Executing a manipulation can lead to code injection.
This vulnerability is registered as CVE-2025-35036. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
ghsa·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] CWE-94 Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
OSV
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
osv·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
OSV
CVE-2025-35036: Hibernate Validator before 6
osv·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] CVE-2025-35036: Hibernate Validator before 6
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
VulnCheck
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
vulncheck·2025·CVSS 6.9
CVE-2025-4428 [MEDIUM] CWE-94 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
Affected: Ivanti Endpoint Manager Mobile (EPMM)
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM; https://www.greynoise.io/blog/ivanti-epmm-z
Red Hat
hibernate-validator: Hibernate Validator Expression Language Injection
vendor_redhat·2025-06-03·CVSS 7.9
CVE-2025-35036 [HIGH] CWE-94 hibernate-validator: Hibernate Validator Expression Language Injection
hibernate-validator: Hibernate Validator Expression Language Injection
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
A flaw was found in Hibernate Validator. This vulnerability allows unauthorized acces
CISA
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
cisa·2025-05-19·CVSS 6.9
CVE-2025-4428 [MEDIUM] CWE-94 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Vulnerability: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Affected: Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4428
Ivanti
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
vendor_ivanti·2025-05-19·CVSS 7.2
CVE-2025-4428 [HIGH] Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
CVE IDs: CVE-2025-4428
This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation Due Date: 2025-06-09
Debian
CVE-2025-35036: libhibernate-validator-java - Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is u...
vendor_debian·2025·CVSS 7.9
CVE-2025-35036 [HIGH] CVE-2025-35036: libhibernate-validator-java - Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is u...
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-35036 resteasy: Hibernate Validator Expression Language Injection [fedora-42]
bugzilla·2025-06-03·CVSS 6.9
CVE-2025-35036 [MEDIUM] CVE-2025-35036 resteasy: Hibernate Validator Expression Language Injection [fedora-42]
CVE-2025-35036 resteasy: Hibernate Validator Expression Language Injection [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2370118
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
P
Bugzilla
CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
bugzilla·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
Discussion:
This issue has been addressed in the following products:
https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontexthttps://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6ehttps://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Finalhttps://github.com/hibernate/hibernate-validator/pull/1138https://hibernate.atlassian.net/browse/HV-1816https://hibernate.org/validator/documentation/migration-guide/#6-2-0-cr1https://in.relation.to/2021/01/06/hibernate-validator-700-62-final-released/#expression-languagehttps://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/https://www.cve.org/CVERecord?id=CVE-2020-5245https://www.cve.org/CVERecord?id=CVE-2025-4428
2025-06-03
Published