Executive Summary



This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary
Informations
Name CVE-2025-35036 First vendor Publication 2025-06-03
Vendor Cve Last vendor Modification 2025-06-03

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-35036

Sources (Detail)

https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single...
https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f4...
https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1...
https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d...
https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e6...
https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0....
https://github.com/hibernate/hibernate-validator/pull/1138
https://hibernate.atlassian.net/browse/HV-1816
https://hibernate.org/validator/documentation/migration-guide/#6-2-0-cr1
https://in.relation.to/2021/01/06/hibernate-validator-700-62-final-released/#...
https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-...
https://www.cve.org/CVERecord?id=CVE-2020-5245
https://www.cve.org/CVERecord?id=CVE-2025-4428
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-06-04 00:20:35
  • First insertion