{"id":"UBUNTU-CVE-2025-35036","details":"Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.","modified":"2026-05-20T16:10:11.379760507Z","published":"2025-06-03T20:15:00Z","upstream":["CVE-2025-35036"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-35036"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-35036"},{"type":"REPORT","url":"https://hibernate.atlassian.net/browse/HV-1816"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/pull/1138"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78"},{"type":"REPORT","url":"https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#section-hibernateconstraintvalidatorcontext"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893"},{"type":"REPORT","url":"https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final"},{"type":"REPORT","url":"https://hibernate.org/validator/documentation/migration-guide/#6-2-0-cr1"},{"type":"REPORT","url":"https://in.relation.to/2021/01/06/hibernate-validator-700-62-final-released/#expression-language"},{"type":"REPORT","url":"https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-5245"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-4428"}],"affected":[{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.2.1-2"],"ecosystem_specific":{"binaries":[{"binary_version":"4.2.1-2","binary_name":"libhibernate-validator-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.3-2","4.3.3-3","4.3.3-4","4.3.4-1~18.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.3.4-1~18.04.1","binary_name":"libhibernate-validator-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-1","5.3.6-1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.3.6-1","binary_name":"libhibernate-validator-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator4-java","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator4-java?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-4~20.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.3.4-4~20.04.1","binary_name":"libhibernate-validator4-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator-java","binary_version":"5.3.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator4-java","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator4-java?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-4"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator4-java","binary_version":"4.3.4-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.6-2"],"ecosystem_specific":{"binaries":[{"binary_version":"5.3.6-2","binary_name":"libhibernate-validator-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator4-java","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator4-java?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-7"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator4-java","binary_version":"4.3.4-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.6-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator-java","binary_version":"5.3.6-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator4-java","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libhibernate-validator4-java?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-7"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator4-java","binary_version":"4.3.4-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator-java","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator-java?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.6-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libhibernate-validator-java","binary_version":"5.3.6-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}},{"package":{"name":"libhibernate-validator4-java","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libhibernate-validator4-java?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4-7"],"ecosystem_specific":{"binaries":[{"binary_version":"4.3.4-7","binary_name":"libhibernate-validator4-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-35036.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}