Visit NES for HSQLDB Home Page
NES for HSQLDB 2.5.x Release Notes
2 versions
Comprehensive release notes and changelog for NES for HSQLDB 2.5.x, including security patches, bug fixes, and feature updates across all supported versions.
October 2026
2.5.4
Released Oct 5, 2026 Full Version:
2.5.2-hsqldb-2.5.4
Security Fixes
- CVE-2022-41853 (Critical) - Remote code execution through Java routines. With the
hsqldb.method_class_namessystem property unset, which is the default, any SQL statement could call any public static Java method on the classpath, so SQL injection into a connection that may execute routines was enough to run arbitrary code. Java methods are now denied unless that property allows them;java.lang.Mathmethods stay allowed. Fixed upstream in 2.7.1.
Breaking Changes
- Java routines are denied unless
hsqldb.method_class_namesallows them. The CVE-2022-41853 fix rejects any Java method that the property doesn't list. This covers aCREATE FUNCTIONorCREATE PROCEDUREwithLANGUAGE JAVA, a legacyCREATE ALIAS, and a quoted method name used directly in a statement. Defining or calling such a routine now fails with SQLSTATE42501(user lacks privilege or object not found), and the message names the denied class.
A database created with an earlier version that already defines such a routine won't open until the property allows the routine's method. The connection fails with SQLSTATES1000(error in script file line: <n> ... user lacks privilege or object not found: <class>). The failed open doesn't change the database; set the property and it opens normally.
Set the property to a semicolon-separated list of the methods, classes, or packages your SQL calls; a value ending in.*allows every name under that prefix, for example-Dhsqldb.method_class_names="com.example.DateUtils.*". HSQLDB reads it once when its classes load, so set it on thejavacommand line rather than withSystem.setProperty()at run time. A bare*or.*is ignored, so no single wildcard allows every class.
2.5.3
Released Oct 5, 2026 Full Version:
2.5.2-hsqldb-2.5.3
Notes
- This release originates from the open-source HSQLDB project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
- This is the initial supported baseline for the 2.5.x line. It is functionally identical to upstream 2.5.2, with no behavioral changes, and contains no vulnerability patches. Security fixes are delivered in subsequent releases on this line.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh