When Hibernate goes EOL, the CVEs don't stop.
Never-Ending Support (NES) for Hibernate keeps the ORM at the heart of your Java data layer secure, compliant, and audit-ready after end of life. NES gives your security team, your engineers, and your leadership back something they lost at EOL: the power to control their own security posture, their own timeline, and where the business focuses its attention.
TRUSTED BY ENTERPRISE

Security, compliance, and continuity, solved together
Hibernate is the ORM at the center of most enterprise Java stacks, but end-of-life versions have stopped receiving upstream security fixes. A recent CVE against Hibernate 5.6, CVE-2026-0603, allows command injection through compromised ID fields, and every scan will flag your build as an unsupported dependency. NES for Hibernate is a supported build of the 5.6 line that turns those open findings into closed ones.
Security
The risk: SQL injection through the JPA Criteria API — and EOL means no upstream fix.
Expert security fixes for the data layer that powers your business, closing the injection paths attackers use to reach unauthorized data.
Immediate protection against SQL injection & data exfiltration
SLA-backed patch delivery tied to severity
Coverage across the Hibernate 5.6 artifact tree
Compliance
The risk: an open audit finding on EOL hibernate-core with no fix path.
Scanners stop flagging CVEs on EOL Hibernate, and every build ships with the documentation your compliance team needs to answer for it.
Documented security patches for compliance teams
Pass audits with documented patch management
Clear the "unsupported software" red flag from scans
Business Continuity
The risk: moving past 5.6 triggers a Boot 2.7 → 3.0 → JDK chain reaction — years of refactoring.
A drop-in Maven artifact with zero migration risk to your object-relational mappings — so you protect the data layer without re-architecting it.
Zero migration risk to complex ORM mappings
Protect customer data without expensive re-architecture
Migrate on your own schedule, not under pressure
YOUR DATA LAYER IS THE ATTACK SURFACE
72%
Hibernate’s share of the Java ORM market across enterprise applications.
130M
records lost by Heartland Payment Systems to a SQL injection attack.
$170M
Sony’s SQL injection breach in damages and recovery costs.
3,700+
enterprises across finance, healthcare and government rely on Hibernate daily.

ECOSYSTEM PARTNERSHIP
The Commonhaus Foundation is a non-profit home for community-governed open source projects, including Jackson, ensuring their long-term stewardship and sustainability. HeroDevs is proud to be the founding member of the Commonhaus Foundation Open Source Sustainability Initiative (OSSI). HeroDevs worked with Commonhaus to establish this security focused initiative and provides Never-Ending Support (NES) for end-of-life versions of Hibernate, and other open-source projects governed by The Commonhaus Foundation.
What changes the day you install NES.
Before — the pain
Your data layer is exposed right now
Hibernate 5.6 stopped receiving security patches. When a SQL injection CVE hits the JPA Criteria API, there's no upstream fix — and the average breach takes 194 days to even identify.
After — with HeroDevs
The ORM goes from exposed to defended
A one-coordinate swap to the NES build resumes SLA-backed CVE patches across the Hibernate 5.6 tree — with your entity mappings and the public API unchanged.
Before — the pain
An open finding with no answer
Internal audit, SOC 2, and a customer security questionnaire all flag EOL hibernate-core. There's no remediation path and no defensible answer for auditors.
After — with HeroDevs
Findings close, questionnaires answer themselves
A named, vendor-backed build with committed SLAs and documented patch management. Scanners stop flagging CVEs and you reference a runtime aligned to PCI DSS, HIPAA, SOC 2, DORA, and NIS2.
Before — the pain
The upgrade breaks everything
Moving beyond Hibernate 5.6 forces a chain reaction: Spring Boot 2.7 → Boot 3.0 → JDK upgrades → dependency rewrites. For most enterprises this isn't a quarter — it's years of refactoring.
After — with HeroDevs
Migrate on your terms, not the clock
A drop-in artifact — no code changes and no risk to your mappings. Teams get the breathing room to plan the Boot and JDK jump properly while the 5.6 line stays secure and compliant.
Real Vulnerabilities fixed on EOL Hibernate.
Command injection doesn't wait for your migration.
65.1%
of all web application attacks now target SQL injection — the vulnerability class that runs straight through your ORM.
$8.7M
regulatory fines that SQL injection attacks alone have cost companies.
$4.88M
average cost of a data breach in 2024 — the highest on record.
194 days
average time to identify a breach — every day increases your attack surface.
The vulnerability class
CVE-2026-0603 is a HIGH-severity command injection vulnerability against hibernate-core, disclosed January 20, 2026, and confirmed present in Hibernate 5.6.0 through 5.6.15. HeroDevs is an authorized CVE Numbering Authority. Our engineers contributed the analyst work on CVE-2026-0603, and NES for Hibernate ships the fix.
Sources: IBM Cost of a Data Breach Report, 2024. HeroDevs Vulnerability Directory, CVE-2026-0603. NVD.
Not just hibernate-core.
NES for Hibernate covers the full Hibernate 5.6 module set: the ORM engine, Jakarta EE variants, caching and connection-pooling integrations, and the OSGi, GraalVM, and observability extensions your services depend on.
Core & ORM
The engine
hibernate-core
hibernate-entitymanager
hibernate-jpamodelgen
hibernate-jcache
Caching & pooling
The plumbing
hibernate-ehcache
hibernate-hikaricp
hibernate-c3p0
hibernate-proxool
Extensions & integrations
The glue
hibernate-envers
hibernate-spatial
hibernate-java8
hibernate-agroal
hibernate-graalvm
A defensible answer for every standard, framework, or regulation
EOL software undermines patch-management expectations across regulations worldwide. NES gives you a maintained, vendor-backed build with committed SLAs and a documented patch history to demonstrate compliance to auditors and regulators.
PCI DSS
Req. 6.3.3 requires known critical and high-severity vulnerabilities to be patched within 30 days. EOL Hibernate with no upstream patch puts you out of compliance. NES restores the patch path.
HIPAA
Unsupported libraries make it hard to show reasonable safeguards for systems handling ePHI. NES provides active maintenance and risk reduction for the data layer.
SOC 2
Trust Services Criteria expect timely vulnerability remediation and patch management. EOL dependencies raise material findings during audit unless a compensating support path exists. NES is that support path.
NIS2
Article 21 covers patching, vulnerability, and supply-chain management. Running EOL software without a maintained support path creates risk that NIS2 expects operators to actively mitigate.
DORA
DORA treats EOL software as a resilience gap for financial ICT assets. NES gives you a maintained build and a documented patch-management program.
Cyber Resilience Act
Governs software lifecycle security for products with digital elements. NES gives you a maintained, patched build for your EOL Quarkus line during the coverage period.
NIST CSF 2.0
Control PR.PS-02 requires organizations to actively maintain or remove vulnerable software based on risk. NES enables compliance without a forced upgrade.
FedRAMP
Continuous monitoring expects flaw remediation on a defined cadence. A patched, vendor-backed build gives your ISSO the documented remediation path to justify keeping EOL Hibernate in the authorization boundary.
Commercial Contracts
Vulnerability and configuration management controls require identifying technical vulnerabilities and keeping software within secure standards. NES restores that posture.
Built by security engineers. Backed by a CNA.
HeroDevs is an authorized CVE Numbering Authority, empowered to discover and assign CVE IDs. Every NES for Hibernate build takes the known-CVE count to zero for covered artifacts and ships with documented security patches your compliance team can map directly to the findings they need to close — so the unsupported-dependency red flag comes off your report.
HeroDevs is also a long-time funder of open source, backing the maintainers and ecosystems that keep software like Hibernate moving forward.
CVE Numbering Authority
Discovery & publication of CVEs
Documented patches
Patch management your auditors accept
Committed SLAs
Severity-tied patch delivery
Frequently Asked Questions
NES is designed to give you full support for as long as you choose to run the covered version. Many customers use it as a runway to a planned Hibernate 5 to 6 or 6 to 7 migration. Others stay on NES indefinitely because the version meets their needs. Both are supported use cases.
Yes. NES gives you a maintained build with committed SLAs, VEX statements, and a documented patch history. Together these give auditors the evidence they expect for PCI DSS 6.3.3, SOC 2 Trust Services Criteria, NIS2 Article 21, DORA, and the EU Cyber Resilience Act, among others.
Through the HeroDevs Maven registry. Add the registry to your settings.xml or pom.xml, authenticate with the credentials you receive on purchase, and update the Hibernate version to the NES tag. See docs.herodevs.com for the specific version tags currently available for Hibernate 5.6.
You update the Hibernate coordinate in your pom.xml to the NES tag and rebuild. Your entities, mappings, queries, extensions, and application code stay unchanged. The build produces the same ORM behavior as your current Hibernate 5.6, with CVE fixes applied.
NES currently covers Hibernate ORM 5.6.x. Coverage for Hibernate ORM 6.6.x is on the roadmap for late 2026, following the June 9, 2026 end of Hibernate 6.6 stable support. Contact us if you're running 6.6 today and want to discuss early access.
NES for Hibernate is a supported build of the Hibernate ORM for organizations running the end-of-life 5.6 line, and (soon) 6.6. It ships as a drop-in Maven artifact that delivers ongoing vulnerability fixes and compliance coverage, giving teams time to plan and execute a migration on their own schedule, or stay indefinitely if the version meets their needs.
Contact Us
Got questions about Never-Ending Support for your open-source library? We're here to help!
Discover how HeroDevs NES Products can keep your systems secure and compliant.
Learn how our solutions can deliver value to your organization.
Get detailed pricing information tailored to your needs.
Stay on Top of Java and JVM Security & Compliance Updates
View All Articles


.png)