CVE-2025-5878 is a vulnerability in ESAPI esapi-java-legacy affecting the SQL Injection Defense interface, specifically Encoder.encodeForSQL. The issue stems from improper neutralization of special elements in SQL-related input handling, meaning the API can give developers a false sense of protection while failing to safely encode attacker-controlled data for SQL contexts. The vulnerable behavior is remotely reachable when an application uses this interface on untrusted input as part of database query construction. Public exploit details are available. The issue was addressed by disabling the feature by default in version 2.7.0.0 and by updating the Java class documentation to warn that the mechanism is unsafe for this purpose.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC consisting of a README and one Python script, esapi-sqlinjection.py. The README states the target is OWASP ESAPI encoder().encodeForSQL() used with OracleCodec(), affecting versions 2.2.0.0 through 2.6.2.0, and recommends upgrading to 2.7.0.0. The Python script implements an HTTP GET-based time-blind SQL injection tool similar in workflow to sqlmap, requiring a target URL with a query parameter and a cookie string. The exploit structure centers on the ESAPISQLExploit class. It extracts the injectable parameter name from the supplied URL, parses cookies, and sends requests with requests.get(). The has_sleep() helper measures response time and treats delays or timeouts as successful boolean conditions. Higher-level methods build SQL payloads that use IF(...,0,SLEEP(5)) or similar constructs to infer data one character at a time. Observed capabilities include: determining the current database name length, extracting the database name, enumerating table counts and table names via information_schema.tables, enumerating column names for a chosen table, and dumping data from selected columns. The CLI supports flags such as --dbs, --tables, --columns, -D, -T, -C, and --dump, indicating a staged workflow: identify database, then tables, then columns, then extract records. The exploit is operational rather than just demonstrative because it contains working request logic, timing checks, cookie handling, and schema/data extraction routines. It is not a detection-only script and does not appear fake. The primary attack vector is web-based exploitation of a vulnerable application endpoint that improperly relies on ESAPI SQL encoding for protection.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.