Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Infinispan

First CVE: Feb 15, 2018Active for: 8 yearsTotal CVEs: 16
22.6
VTI Score
Low

Infinispan is a distributed caching and data-grid platform widely embedded in enterprise middleware and application servers, particularly within the JBoss and Red Hat ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity; the exposure centers on the core Infinispan cache server and its REST and Hot Rod protocol endpoints, and recurs through weakness classes including deserialization of untrusted data, improper authentication, and missing authorization checks that are characteristic of remote-access middleware. Defenders should treat Infinispan updates as high-priority within their application-server inventory and focus on controls around cache-server network exposure; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Infinispan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 15, 2018
8 years ago
Most Recent CVE
Jun 26, 2025
393 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-31917CRITICAL
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when
Sep 21, 20219.830NONO
CVE-2019-10158CRITICAL
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect
Jan 2, 20209.830NONO
CVE-2019-10174HIGH
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla
Nov 25, 20198.829NONO
CVE-2016-0750HIGH
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecti
Sep 11, 20188.828NONO
CVE-2017-15089HIGH
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a mal
Feb 15, 20188.827NONO
CVE-2018-1131HIGH
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could s
May 15, 20188.826NONO
CVE-2020-10771HIGH
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform
Jun 2, 20217.124NONO
CVE-2017-2638MEDIUM
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the
Jul 16, 20186.523NONO
CVE-2023-4586HIGH
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in
Oct 4, 20237.422NONO
CVE-2020-25711MEDIUM
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with
Dec 3, 20206.522NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
44%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (12.5%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None15 (93.8%)
Unknown0 (0.0%)
Required1 (6.3%)
Privileges Required
Low9 (56.3%)
High2 (12.5%)
None5 (31.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Infinispan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Infinispan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Infinispan's Products

View all 1 CNAs →

Top CWEs