Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hazelcast

First CVE: May 22, 2019Active for: 7 yearsTotal CVEs: 9

Hazelcast's vulnerability footprint centers on its in-memory data grid and streaming products, which serve as critical caching and real-time processing layers in distributed architectures. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster around unsafe deserialization, improper authentication, code injection, SQL injection, and XML external entity handling—weaknesses characteristic of data-tier components that parse untrusted input and manage access to shared state. Defenders should prioritize patches for this vendor's releases, particularly for internet-accessible or boundary-facing deployments; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hazelcast over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2019
7 years ago
Most Recent CVE
Apr 17, 2025
463 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0265CRITICAL
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
Mar 3, 20229.832NONO
CVE-2020-26168CRITICAL
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some sy
Nov 9, 20209.830NONO
CVE-2024-56518CRITICAL
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), w
Apr 17, 20259.829NONO
CVE-2022-36437CRITICAL
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already aut
Dec 29, 20229.128NONO
CVE-2023-33265HIGH
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on me
Jul 18, 20238.826NONO
CVE-2023-45859HIGH
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions prope
Feb 28, 20247.622NONO
CVE-2016-10750HIGH
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a
May 22, 20198.121NONO
CVE-2023-45860MEDIUM
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which
Feb 16, 20246.520NONO
CVE-2023-33264MEDIUM
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Manage
May 22, 20234.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
33%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hazelcast.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hazelcast — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hazelcast's Products

View all 2 CNAs →

Top CWEs