CVE-2019-10219

Executive Summary

CVE-2019-10219 exposes a flaw in Hibernate Validator’s SafeHtml annotation, which fails to strip malicious code embedded in HTML comments or instruction blocks. Attackers can inject XSS payloads that bypass the validator, enabling script execution in victim browsers. The vulnerability affects any application using Hibernate Validator for input sanitization, potentially compromising user data and session integrity.


Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2019-11-08T15:15:11.157 - Last Modified: 2026-08-21T14:32:12.107

Original Description: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

"Time stays long enough for anyone who will use it."

— Leonardo da Vinci
Source: NVD