When Hibernate goes EOL, the CVEs don't stop.

Never-Ending Support (NES) for Hibernate keeps the ORM at the heart of your Java data layer secure, compliant, and audit-ready after end of life. NES gives your security team, your engineers, and your leadership back something they lost at EOL: the power to control their own security posture, their own timeline, and where the business focuses its attention.

TRUSTED BY ENTERPRISE

Google logoMicrosoft logoFinra logoBank Santander Logo
Hitachi LogoWorkday logoDropbox logo

Security, compliance, and continuity, solved together

Hibernate is the ORM at the center of most enterprise Java stacks, but end-of-life versions have stopped receiving upstream security fixes. A recent CVE against Hibernate 5.6, CVE-2026-0603, allows command injection through compromised ID fields, and every scan will flag your build as an unsupported dependency. NES for Hibernate is a supported build of the 5.6 line that turns those open findings into closed ones.

Security

The risk: SQL injection through the JPA Criteria API — and EOL means no upstream fix.

Expert security fixes for the data layer that powers your business, closing the injection paths attackers use to reach unauthorized data.

Immediate protection against SQL injection & data exfiltration

SLA-backed patch delivery tied to severity

Coverage across the Hibernate 5.6 artifact tree

Compliance

The risk: an open audit finding on EOL hibernate-core with no fix path.

Scanners stop flagging CVEs on EOL Hibernate, and every build ships with the documentation your compliance team needs to answer for it.

Documented security patches for compliance teams

Pass audits with documented patch management

Clear the "unsupported software" red flag from scans

Business Continuity

The risk: moving past 5.6 triggers a Boot 2.7 → 3.0 → JDK chain reaction — years of refactoring.

A drop-in Maven artifact with zero migration risk to your object-relational mappings — so you protect the data layer without re-architecting it.

Zero migration risk to complex ORM mappings

Protect customer data without expensive re-architecture

Migrate on your own schedule, not under pressure

“We had three options: 1) migrate to a new framework (expensive, time consuming and disruptive to planned roadmap), 2) maintain the framework ourselves (diversion of development resources), 3) engage with HeroDevs for never ending support as a subscription (budget able annual expense, no impact to dev plan)… Implementation was super simple. With the implementation of the HeroDevs libraries, 100% of the known vulnerabilities in the AngularJS framework were remediated yielding a clean scan via Burp Suite for our monthly POA&M.”

— ViTel Net
Enterprise healthcare IT

“By leveraging HeroDevs’ extended support, we were able to mitigate security risks, continue safe operation of the legacy application, and gain valuable time to plan a more sustainable long-term migration strategy — all without compromising on client experience or regulatory requirements.”

— Sanlam Private Wealth
Financial services

“We were caught in the classic technology dilemma – spend valuable engineering time updating a legacy system we were already planning to replace, or accept increasing security risk. Neither option aligned with our business objectives. … With NES we maintained our security posture without compromising our strategic roadmap, all while achieving substantial cost savings.”

— Statista
Markus Wolf, Architect

“Imagine telling your customers you can’t deliver any of the features they’ve been asking for because you need to spend the next year rewriting code that already works. That’s not a conversation any CTO wants to have… The impact [of NES] goes beyond just keeping our lights on — we’ve been able to invest in a completely new component library, improve user experiences, and deliver features that directly contribute to new customer acquisition. That wouldn’t have been possible if we’d been stuck in migration mode.”

— Keelvar
Valentina Roques, CTO

YOUR DATA LAYER IS THE ATTACK SURFACE

72%

Hibernate’s share of the Java ORM market across enterprise applications.

130M

records lost by Heartland Payment Systems to a SQL injection attack.

$170M

Sony’s SQL injection breach in damages and recovery costs.

3,700+

enterprises across finance, healthcare and government rely on Hibernate daily.

Commonhaus Foundation

ECOSYSTEM PARTNERSHIP

The Commonhaus Foundation is a non-profit home for community-governed open source projects, including Jackson, ensuring their long-term stewardship and sustainability. HeroDevs is proud to be the founding member of the Commonhaus Foundation Open Source Sustainability Initiative (OSSI). HeroDevs worked with Commonhaus to establish this security focused initiative and provides Never-Ending Support (NES) for end-of-life versions of Hibernate, and other open-source projects governed by The Commonhaus Foundation.

What changes the day you install NES.

Before — the pain

Your data layer is exposed right now

Hibernate 5.6 stopped receiving security patches. When a SQL injection CVE hits the JPA Criteria API, there's no upstream fix — and the average breach takes 194 days to even identify.

After — with HeroDevs

The ORM goes from exposed to defended

A one-coordinate swap to the NES build resumes SLA-backed CVE patches across the Hibernate 5.6 tree — with your entity mappings and the public API unchanged.

Before — the pain

An open finding with no answer

Internal audit, SOC 2, and a customer security questionnaire all flag EOL hibernate-core. There's no remediation path and no defensible answer for auditors.

After — with HeroDevs

Findings close, questionnaires answer themselves

A named, vendor-backed build with committed SLAs and documented patch management. Scanners stop flagging CVEs and you reference a runtime aligned to PCI DSS, HIPAA, SOC 2, DORA, and NIS2.

Before — the pain

The upgrade breaks everything

Moving beyond Hibernate 5.6 forces a chain reaction: Spring Boot 2.7 → Boot 3.0 → JDK upgrades → dependency rewrites. For most enterprises this isn't a quarter — it's years of refactoring.

After — with HeroDevs

Migrate on your terms, not the clock

A drop-in artifact — no code changes and no risk to your mappings. Teams get the breathing room to plan the Boot and JDK jump properly while the 5.6 line stays secure and compliant.

Real Vulnerabilities fixed on EOL Hibernate.

HeroDevs is an authorized CVE Numbering Authority (CNA). The advisories below are real vulnerabilities existent on EOL Hibernate versions. Switch to NES for immediate patches containing fixes to known CVEs. Every fix is published, one advisory per entry.
Severity
ID
Category
Version(s) Affected
Published Date
High
Command Injection
>= 5.6.0 <= 5.6.15
Jan 20, 2026

Command injection doesn't wait for your migration.

CVE-2026-0603 targets Hibernate 5.6's InlineIdsOrClauseBuilder, letting attackers use a compromised ID field to execute unauthorized SQL on subsequent updates and deletes. In internal testing, the exploit could delete every row in a table and read the contents of the application server's filesystem. Hibernate 5.6 no longer receives community patches, so this finding stays open on every build until you migrate or install NES.
Severity
CVE
Category
Version(s) Affected
Published Date
Medium
Improper Input Validation (4.16)
>=0.16.0 <2.0.10 >=3.0.0 <3.0.6 >=4.0.0 <4.1.0
Jul 14, 2026
Medium
Denial of Service
<20.20.2 >=22.0.0 <22.22.2 >=24.0.0 <24.14.1 >=25.0.0 <25.8.2
Apr 13, 2026
High
Uncontrolled Resource Consumption
v4 < v20.20.0, v22 < v22.22.0, v24 < v24.13.0, v25 < v25.3.0
Jan 13, 2026
High
Path Traversal
4.0 < 20.19.4, 22 < 22.17.1, 24 < 24.4.1
Jul 15, 2025
Medium
HTTP Request Smuggling
4.0 < 20.19.1
May 14, 2025
High
Cryptographic Weakness
4.0 < 20.19.1, 22 < 22.15.0, 24 < 24.0.1
May 14, 2025
Medium
Denial of Service
4.0 < 18.20.6, 20 < 20.18.2
Feb 7, 2025
Medium
Path Traversal
4.0 < 18.20.6, 20 < 20.18.2
Jan 28, 2025
High
Command Injection
4.0 <= 18.20.2, 20 < 20.12.2
Jan 9, 2025
High
HTTP Request Smuggling
>=16.0.0 <16.20.1, >=18.0.0 <18.16.1, >=20.0.0 <20.3.1
Oct 16, 2024
Low
Information Exposure
>=16.0.0 <=16.20.2
Oct 15, 2024
Medium
Denial of Service
>=14.0.0 <=14.21.3, >=16.0.0 <=16.20.2
Oct 15, 2024
Medium
Cryptographic Weakness
4.0 < 18.19.1, 20 < 20.11.1
Sep 7, 2024
High
Command Injection
4.0 < 18.20.4, 20.0 < 20.15.1, 22.0< 22.4.1
Sep 7, 2024
Medium
HTTP Request Smuggling
4.0 < 18.20.1, 20 < 20.12.1
May 7, 2024
Medium
HTTP Request Smuggling
<21.7.2, <20.12.1, <v18.20.1, <= 16.20.2, <=v14.21.3, <= v12.22.12
May 1, 2024
High
Uncontrolled Resource Consumption
4 <= 18.20.0, 20 <= 20.12.0
Apr 9, 2024
High
Privilege Escalation
4.0 < 18.19.1, 20 < 20.11.1
Feb 20, 2024
Medium
Denial of Service
<21.6.2, <20.11.1, <v18.19.1, <= 16.20.2
Feb 14, 2024
High
Denial of Service
<21.6.2, <20.11.1, <v18.19.1, <= 16.20.2, <=v14.21.3, <= v12.22.12
Feb 14, 2024
Medium
Cryptographic Weakness
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Nov 28, 2023
Medium
Insufficient Verification of Data Authenticity
4.0 <= 18.18.1, 20 < 20.8.1
Oct 18, 2023
Medium
Privilege Escalation
4 <= 16.20.1, 0 <= 18.17.0, 0 <= 20.5.0
Aug 24, 2023
Medium
HTTP Request Smuggling
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Jun 30, 2023
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Dec 5, 2022
High
Resource Injection
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
High
Authorization Bypass
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022

65.1%

of all web application attacks now target SQL injection — the vulnerability class that runs straight through your ORM.

$8.7M

regulatory fines that SQL injection attacks alone have cost companies.

$4.88M

average cost of a data breach in 2024 — the highest on record.

194 days

average time to identify a breach — every day increases your attack surface.

The vulnerability class

CVE-2026-0603 is a HIGH-severity command injection vulnerability against hibernate-core, disclosed January 20, 2026, and confirmed present in Hibernate 5.6.0 through 5.6.15. HeroDevs is an authorized CVE Numbering Authority. Our engineers contributed the analyst work on CVE-2026-0603, and NES for Hibernate ships the fix.

Vulnerability Directory
White arrow

Sources: IBM Cost of a Data Breach Report, 2024. HeroDevs Vulnerability Directory, CVE-2026-0603. NVD.

Not just hibernate-core.

NES for Hibernate covers the full Hibernate 5.6 module set: the ORM engine, Jakarta EE variants, caching and connection-pooling integrations, and the OSGi, GraalVM, and observability extensions your services depend on.

Core & ORM

The engine

hibernate-core

hibernate-entitymanager

hibernate-jpamodelgen

hibernate-jcache

Caching & pooling

The plumbing

hibernate-ehcache

hibernate-hikaricp

hibernate-c3p0

hibernate-proxool

Extensions & integrations

The glue

hibernate-envers

hibernate-spatial

hibernate-java8

hibernate-agroal

hibernate-graalvm

A defensible answer for every standard, framework, or regulation

EOL software undermines patch-management expectations across regulations worldwide. NES gives you a maintained, vendor-backed build with committed SLAs and a documented patch history to demonstrate compliance to auditors and regulators.

PCI DSS

US

Req. 6.3.3 requires known critical and high-severity vulnerabilities to be patched within 30 days. EOL Hibernate with no upstream patch puts you out of compliance. NES restores the patch path.

HIPAA

US

Unsupported libraries make it hard to show reasonable safeguards for systems handling ePHI. NES provides active maintenance and risk reduction for the data layer.

SOC 2

Global

Trust Services Criteria expect timely vulnerability remediation and patch management. EOL dependencies raise material findings during audit unless a compensating support path exists. NES is that support path.

NIS2

EU

Article 21 covers patching, vulnerability, and supply-chain management. Running EOL software without a maintained support path creates risk that NIS2 expects operators to actively mitigate.

DORA

EU

DORA treats EOL software as a resilience gap for financial ICT assets. NES gives you a maintained build and a documented patch-management program.

Cyber Resilience Act

EU

Governs software lifecycle security for products with digital elements. NES gives you a maintained, patched build for your EOL Quarkus line during the coverage period.

NIST CSF 2.0

US

Control PR.PS-02 requires organizations to actively maintain or remove vulnerable software based on risk. NES enables compliance without a forced upgrade.

FedRAMP

US

Continuous monitoring expects flaw remediation on a defined cadence. A patched, vendor-backed build gives your ISSO the documented remediation path to justify keeping EOL Hibernate in the authorization boundary.

Commercial Contracts

Global

Vulnerability and configuration management controls require identifying technical vulnerabilities and keeping software within secure standards. NES restores that posture.

Built by security engineers. Backed by a CNA.

HeroDevs is an authorized CVE Numbering Authority, empowered to discover and assign CVE IDs. Every NES for Hibernate build takes the known-CVE count to zero for covered artifacts and ships with documented security patches your compliance team can map directly to the findings they need to close — so the unsupported-dependency red flag comes off your report.

HeroDevs is also a long-time funder of open source, backing the maintainers and ecosystems that keep software like Hibernate moving forward.

CVE Numbering Authority

Discovery & publication of CVEs

Documented patches

Patch management your auditors accept

Committed SLAs

Severity-tied patch delivery

Frequently Asked Questions

Is NES a permanent alternative to upgrading?
Does NES for Hibernate help with compliance?
How is it delivered?
What does drop-in replacement for EOL Hibernate mean?
Which Hibernate version does NES support?
What is Never-Ending Support (NES) for Hibernate?

Contact Us

Got questions about Never-Ending Support for your open-source library? We're here to help!

Discover how HeroDevs NES Products can keep your systems secure and compliant.

Learn how our solutions can deliver value to your organization.

Get detailed pricing information tailored to your needs.

Google logoLilly logoAbbott logoBox logoEG logoHitachi logoDropbox logoNHS logoWorkday logoFinra logoMicrosoft logoSantander logo
Talk to an Expert

By submitting the form I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.