OWASP Java Encoder 1.5.0
Version 1.5.0 is available from Maven Central. All nine binary/source/Javadoc JARs, four POMs, and their thirteen signatures were downloaded from Central and verified against the retained signed release files. There is no encoder-esapi:1.5.0 release.
Security and correctness
- Fixes encoded fragments completing outer HTML or XML parser delimiters across trusted-text boundaries in JavaScript HTML/block, CDATA, and XML-comment contexts. Versions through 1.4.1 are affected. See GHSA-g8p6-7r8f-qrpv.
- Fixes
EncodedWriterclose/finalization behavior, exception handling, and overflow-safe array-slice validation. - Adds JSON encoding APIs and matching JSP/Jakarta tags and EL functions, plus XML 1.1 bindings.
Compatibility and migration
Public Java APIs remain binary and source compatible with 1.4.1 for the three supported libraries. Java 8 remains the minimum runtime; packaged consumers passed on Java 8, 11, 17, 21, and 25.
The security fixes deliberately change some encoded output:
- JavaScript HTML/block modes emit additional hexadecimal escapes while preserving the string value. Review byte snapshots, cache keys, signatures, and output-size budgets.
- CDATA preserves parsed text but can expand to 13 output characters per input character and can change parser event boundaries.
- XML-comment hyphens become
~under the documented lossy policy.
The optional ESAPI adapter is retired. Version 1.4.1 is its final published release and is unsupported; migrate to direct Java Encoder APIs. Mixing the 1.4.1 adapter with the 1.5 core is not a supported migration.
See the migration notes, ESAPI retirement guide, and changelog.
Maven artifacts
Use group org.owasp.encoder and version 1.5.0:
- encoder
- encoder-jsp
- encoder-jakarta-jsp
- encoder-parent (parent POM)
The optional test WAR and retired ESAPI adapter are not published.
Verification
Exact release source: 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. The signed v1.5.0 tag identifies this tested commit. PR #229's squash commit 030c137fc14f277afc5fbe303d2ca8a149f8068b has the identical file tree.
Release artifacts were built with Eclipse Temurin 17.0.20.1+1 and the committed Maven 3.9.16 wrapper. All 2,287 local reactor tests passed with zero failures, errors, or skips. All thirteen unsigned payload files matched two fresh source-export builds. Post-merge Java CI, packaged consumers, and CodeQL passed, including the browser and Java 8 gates.
Project signing fingerprint: 1C5F632B86809F2F5DB25092BEA0075F94074A9B.
The assets contain the public KEYS, detached signatures, and signed SHA-256/SHA-512 manifests. Follow the verification instructions, using this full expected fingerprint and the 1.5.0 filenames. Authenticate each checksum manifest's signature before checking its entries.
Central bundle SHA-256: 107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.
The source-tag documentation preserves the pre-publication notices from the immutable release commit. This release record confirms the subsequently verified Central publication; publication follow-up documentation belongs in a later commit, not a rebuilt release.