The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
Moderate severity
GitHub Reviewed
Published
Jan 8, 2020
to the GitHub Advisory Database
•
Updated Aug 11, 2025
Package
Affected versions
>= 6.1.0.Alpha1, < 6.1.0.Alpha6
>= 6.0.0.Alpha1, <= 6.0.17.Final
Patched versions
6.1.0.Alpha6
6.0.18.Final
Description
Published by the National Vulnerability Database
Nov 8, 2019
Reviewed
Jan 8, 2020
Published to the GitHub Advisory Database
Jan 8, 2020
Last updated
Aug 11, 2025
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
References