Cyber Resilience
← All news
Confirmed

HSQLDB: CVSS (Max): 5.0

Our takeThis AUSCERT batch spans HSQLDB (5.0) to PHP (9.8) and dracut (8.8). Don't let the modest HSQLDB score set your priority — check which of these eight you actually run and patch PHP and dracut first if so.
Sources (14)
What this means for you — Security leader:Update HSQLDB to a fixed version if you run it; the CVSS 5.0 flaw is now confirmed.
What this means for you — Lean IT orgs:If your software or database uses HSQLDB, check with the vendor for an update. Most small teams can ignore this one unless a specific app you run depends on it.
What this means for you — MSP:Audit client estates for any use of HSQLDB and apply the vendor update where present.
What this means for you — Researcher:HSQLDB advisory (ESB-2026.10707) lists a confirmed CVSS 5.0 issue; review the linked AUSCERT bulletin for affected versions and patches.