ESAPI 2.7.0.0 released; addresses CVE-2025-5878 and others in vulnerable dependencies

9 views
Skip to first unread message

Kevin W. Wall

unread,
Jun 27, 2025, 9:39:49 PMJun 27
to esapi-project-users
See the announcement in GitHub Discussion #889 and be sure to read the referenced Security Bulletin #13 mentioned therein.

(Note: To my knowledge, the CVE has not yet been made public, but I expect that to happen shortly.)

-kevin wall
--
Blog: https://off-the-wall-security.blogspot.com/    | GitHub: @kwwall | OWASP ESAPI Project co-lead | OWASP and ACM lifetime member
NSA: All your crypto bit are belong to us.
Reply all
Reply to author
Forward
0 new messages