Hazelcast's vulnerability footprint centers on its in-memory data grid and streaming products, which serve as critical caching and real-time processing layers in distributed architectures. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster around unsafe deserialization, improper authentication, code injection, SQL injection, and XML external entity handling—weaknesses characteristic of data-tier components that parse untrusted input and manage access to shared state. Defenders should prioritize patches for this vendor's releases, particularly for internet-accessible or boundary-facing deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hazelcast over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0265CRITICAL Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. | Mar 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-26168CRITICAL The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some sy | Nov 9, 2020 | 9.8 | 30 | NO | NO |
CVE-2024-56518CRITICAL Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), w | Apr 17, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-36437CRITICAL The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already aut | Dec 29, 2022 | 9.1 | 28 | NO | NO |
CVE-2023-33265HIGH In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on me | Jul 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-45859HIGH In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions prope | Feb 28, 2024 | 7.6 | 22 | NO | NO |
CVE-2016-10750HIGH In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a | May 22, 2019 | 8.1 | 21 | NO | NO |
CVE-2023-45860MEDIUM In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which | Feb 16, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-33264MEDIUM In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Manage | May 22, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hazelcast.
Media articles that mention a CVE ID that affects a product developed by Hazelcast — matched by CVE ID, not by vendor name.