Visit NES for HSQLDB Home Page

NES for HSQLDB 2.5.x Release Notes

2 versions

Comprehensive release notes and changelog for NES for HSQLDB 2.5.x, including security patches, bug fixes, and feature updates across all supported versions.

Oct 5, 2026
Latest: 2.5.4
1 Patched Vulnerability
VEX Statements

October 2026

2.5.4

Released Oct 5, 2026
Full Version:
2.5.2-hsqldb-2.5.4

Security Fixes

  • CVE-2022-41853 (Critical) - Remote code execution through Java routines. With the hsqldb.method_class_names system property unset, which is the default, any SQL statement could call any public static Java method on the classpath, so SQL injection into a connection that may execute routines was enough to run arbitrary code. Java methods are now denied unless that property allows them; java.lang.Math methods stay allowed. Fixed upstream in 2.7.1.

Breaking Changes

  • Java routines are denied unless hsqldb.method_class_names allows them. The CVE-2022-41853 fix rejects any Java method that the property doesn't list. This covers a CREATE FUNCTION or CREATE PROCEDURE with LANGUAGE JAVA, a legacy CREATE ALIAS, and a quoted method name used directly in a statement. Defining or calling such a routine now fails with SQLSTATE 42501 (user lacks privilege or object not found), and the message names the denied class.
    A database created with an earlier version that already defines such a routine won't open until the property allows the routine's method. The connection fails with SQLSTATE S1000 (error in script file line: <n> ... user lacks privilege or object not found: <class>). The failed open doesn't change the database; set the property and it opens normally.
    Set the property to a semicolon-separated list of the methods, classes, or packages your SQL calls; a value ending in .* allows every name under that prefix, for example -Dhsqldb.method_class_names="com.example.DateUtils.*". HSQLDB reads it once when its classes load, so set it on the java command line rather than with System.setProperty() at run time. A bare * or .* is ignored, so no single wildcard allows every class.

2.5.3

Released Oct 5, 2026
Full Version:
2.5.2-hsqldb-2.5.3

Notes

  • This release originates from the open-source HSQLDB project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This is the initial supported baseline for the 2.5.x line. It is functionally identical to upstream 2.5.2, with no behavioral changes, and contains no vulnerability patches. Security fixes are delivered in subsequent releases on this line.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.