// OSSeva Blog
SecurityGemFire and Geode Vulnerabilities by Version: CVEs for Tanzu GemFire 9.x and 10.x and Apache Geode 1.x and 2.x
The short answer
Broadcom supports three GemFire lines: 10.1 until 28 February 2027, 10.2 until 31 October 2028 and 10.3 until 31 July 2029. General support for 10.0 ended on 30 April 2026 and for 9.15 on 31 October 2025, and their last patches were 10.0.8 and 9.15.16. On the open source side, the Apache Geode project voted in March 2026 to support only 2.0.x and 1.15.x and to declare 1.14.x and every earlier line end of life, with no further bug fixes, security fixes or backports. Geode's own CVEs since 2022 are fixed only from 1.15, so a cluster on 1.14 or older is missing them and will get no fix.
The two products now get most of their security fixes the same way: as updates to the libraries they bundle. Broadcom's advisory for GemFire 10.3.2, published on 2 October 2026, lists 36 resolved vulnerabilities, and Geode 2.0.3 in September 2026 updated Shiro, Jetty, Jackson, Bouncy Castle and Log4j among others. A line that stops getting releases stops getting those updates too.
GemFire and Geode release lines and their CVEs
GemFire dates are from Broadcom's product lifecycle table and the GemFire release notes. Geode dates and support status are from the Apache release records, the Geode release announcements and the result of the Geode support vote on 11 March 2026.
| Line | Upstream status | Latest release | Notable CVEs | Upstream fix on this line |
|---|---|---|---|---|
| GemFire 10.3 | General support to 31 July 2029; JDK 17 minimum | 10.3.2, 22 September 2026 | 36 vulnerabilities in Broadcom's 10.3.2 advisory, led by CVE-2026-71290 in the bundled HttpComponents Client | 10.3.2 |
| GemFire 10.2 | General support to 31 October 2028 | 10.2.8, 22 September 2026 | Broadcom's 10.2.8 advisory, also rated critical | 10.2.8 |
| GemFire 10.1 | General support to 28 February 2027 | 10.1.9, 18 August 2026 | Bundled-library fixes such as CVE-2025-67735 in Netty, fixed in 10.1.6 | 10.1.9; further 10.1 patches until February 2027 |
| GemFire 10.0 | General support ended 30 April 2026 | 10.0.8, 17 March 2026 | Fixes shipped in 10.1.8, 10.1.9 and later releases | No upstream fix on this line |
| GemFire 9.15 | General support ended 31 October 2025 | 9.15.16, 8 July 2025 | Every fix Broadcom has shipped since July 2025 | No upstream fix on this line; 9.15.3 fixed CVE-2022-34870 |
| GemFire 9.10 and older | 9.10 general support ended 31 December 2024 | 9.10.17, 3 November 2022 | CVE-2019-11286 and CVE-2020-5396 before 9.10.0 | No upstream fix on these lines |
| Geode 2.0 | Supported; current major line, Java 17 and Jakarta EE 10 | 2.0.3, September 2026 | Bundled-library fixes, including CVE-2026-49268 in Shiro | 2.0.3 |
| Geode 1.15 | Supported; final 1.x line | 1.15.5, September 2026 | CVE-2025-47410 and CVE-2024-44088 before 1.15.2 | 1.15.2 to 1.15.5 |
| Geode 1.14 | End of life by PMC vote, 11 March 2026 | 1.14.4, March 2022 | CVE-2025-47410, CVE-2024-44088, CVE-2022-37023, CVE-2022-34870; CVE-2022-37021 on 1.14.0 | No upstream fix on this line |
| Geode 1.13 and 1.12 | End of life | 1.13.8; 1.12.9, June 2022 | The 1.14 list, plus CVE-2022-37021 and CVE-2022-37022 on the earlier patch releases | No upstream fix on these lines |
The releases page on geode.apache.org lists nothing after 2.0.0 and 1.15.2, so the newer releases are recorded in the dev list announcements and the Apache release archive. GemFire shares its code base with Geode, and Broadcom lists some Geode CVEs in its release notes: 9.15.3 fixed CVE-2022-34870. The GemFire notes do not list CVE-2024-44088 or CVE-2025-47410, so whether a given GemFire build is exposed to them is a question for Broadcom. For every date in one place, see the GemFire and Geode end-of-life tracker.
Notable GemFire and Geode CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2022-37021 | JMX over RMI on Java 8 deserializes untrusted data | 9.8 (NVD) | Geode 1.12.5 and earlier; 1.13.0 to 1.13.4; 1.14.0 | Geode 1.15.0 on Java 11, or on Java 8 with -Dgeode.enableGlobalSerialFilter=true |
| CVE-2017-15692 | The locator's TcpServer deserializes data from its network port, which can run code if certain classes are on the classpath | 9.8 (NVD) | Geode before 1.4.0 | Geode 1.4.0 |
| CVE-2019-11286 | A JMX service on the network does not restrict input, so an authenticated user with crafted credentials can run code | 9.1 (NVD) | GemFire before 9.7.5; 9.8.0 to 9.8.4; 9.9.0 | GemFire 9.7.5, 9.8.5, 9.9.1, 9.10.0 |
| CVE-2020-5396 | Without a SecurityManager, the JMX service lets a user create an MLet MBean and run code | 8.8 (NVD) | GemFire before 9.7.6; 9.8.0 to 9.8.6; 9.9.0 to 9.9.1 | GemFire 9.7.6, 9.8.7, 9.9.2, 9.10.0 |
| CVE-2025-47410 | GET requests to the Management and Monitoring REST API are open to CSRF, so a tricked user's session can run gfsh commands | 8.8 (CISA-ADP) | Geode 1.10.0 to 1.15.1 | Geode 1.15.2 |
| CVE-2022-37022 | JMX over RMI on Java 11 deserializes untrusted data | 8.8 (NVD) | Geode 1.12.2 and earlier; 1.13.0 to 1.13.2 | Geode 1.15.0 |
| CVE-2021-34797 | Log redaction misses passwords and security properties that start with a character other than a letter or digit | 7.5 (NVD) | Geode 1.12.4 and earlier; 1.13.0 to 1.13.4 | Geode 1.12.5, 1.13.5, 1.14.0 |
| CVE-2022-37023 | The REST API deserializes untrusted data on Java 8 and Java 11 | 6.5 (NVD) | Geode before 1.15.0 | Geode 1.15.0, with validate-serializable-objects=true |
| CVE-2024-44088 | Reflected cross-site scripting in the REST web API can lead to session theft | 6.1 (CISA-ADP) | Geode 1.1.0 to 1.15.1 | Geode 1.15.2 |
| CVE-2022-34870 | Stored cross-site scripting through region entries viewed in the Pulse web application | 5.4 (NVD) | Geode 1.15.0 and earlier | Geode 1.15.1; GemFire 9.15.3 |
The serious rows share one shape. GemFire and Geode expose JMX, a locator port and REST endpoints, and every remote code execution above goes through one of them, mostly by way of Java deserialization. Since 1.15 the fixes depend on configuration as much as on the release: CVE-2022-37021 needs Java 11, or the global serial filter on Java 8, and CVE-2022-37023 needs validate-serializable-objects set to true, which is off by default. The newer CVE-2025-47410 and CVE-2024-44088 matter wherever the Management and Monitoring REST API or the developer REST API is reachable from a browser, because both work by tricking a logged-in user.
The bundled libraries carry most of the recent volume. CVE-2026-71290, scored 9.1 by CISA-ADP, is a hostname verification flaw in the async client of Apache HttpComponents Client 5.4 and later, fixed in GemFire 10.3.2. Geode 1.15.3 addressed CVE-2025-48924 in Commons Lang and a resource exhaustion issue, and Geode 2.0.3 updated Shiro from 2.1.0 to 3.0.0 for CVE-2026-49268.
What each line gets
GemFire 10.2 and 10.3
Both are supported for years yet, and 10.2.8 and 10.3.2 are the current patches. 10.3 needs JDK 17 and moves to Jakarta EE, so 10.2 is the line for clusters that cannot change their JDK or their application libraries yet. Both accept a direct upgrade from any 10.x release.
GemFire 10.1 and 10.0
10.1 is still patched, most recently 10.1.9 in August 2026, but its support ends on 28 February 2027. 10.0 stopped at 10.0.8 in March 2026 and does not have the 10.1.8 changes that limit queued connections on servers and locators to resist resource exhaustion. Moving to 10.2 or 10.3 is a direct upgrade from either. See GemFire 10.0 end of life.
GemFire 9.15 and older
9.15.16, from July 2025, was the last 9.x patch. The release notes require a 9.x cluster to pass through 10.1 before 10.2 or 10.3, and a cluster on 9.15.13 or later must land on 10.1.2 or later. CVE-2019-11286 and CVE-2020-5396 matter only to clusters on 9.9 or earlier without the patch releases that fixed them. See GemFire 9.15 end of life and upgrading GemFire 9.15 and 10.0 to 10.2 or 10.3.
Geode 2.0 and 1.15
These are the two lines the Geode project supports. 1.15.2 fixed the two 2025 CVEs. 1.15.3 and 1.15.4 in 2026 added security and dependency updates and 1.15.5 bug fixes, and each of those announcements points users to the latest 2.0.x release. Geode 2.0 needs Java 17 and moves to Jakarta EE 10, so it is a bigger step than a patch upgrade.
Geode 1.14 and older
The March 2026 vote ended all support for these lines. 1.14.4, from 2022, lacks the 2025 CSRF and cross-site scripting fixes and the 1.15 deserialization controls, and 1.12 and 1.13 also lack the JMX over RMI fixes. The supported path is 1.14 to 1.15 within 1.x, then 1.15 to 2.0.
What to do on each line
- GemFire 10.2 and 10.3. Take 10.2.8 or 10.3.2, and subscribe to Broadcom's Tanzu security advisories, which is where the per-release vulnerability lists appear.
- GemFire 10.0 and 10.1. Move to 10.2 or 10.3 before 10.1 support ends in February 2027.
- GemFire 9.x. Plan the two-step upgrade through 10.1, the move to Apache Geode, or patched builds from a supplier that backports fixes. Until then, run with a SecurityManager, keep JMX, locator and REST ports off untrusted networks, and keep Pulse and the REST APIs away from browsers on shared networks.
- Geode 1.14 and older. Move to 1.15.5, then plan 2.0. On 1.15, set validate-serializable-objects=true with a serializable-object-filter, and on Java 8 start locators and servers with -Dgeode.enableGlobalSerialFilter=true.
For teams weighing a move off the commercial product, see moving from Tanzu GemFire to Apache Geode and the open source paths off VMware Tanzu products.
Where OSSeva fits
OSSeva ships patched builds for GemFire 9.x and 10.x and Apache Geode 1.14, 1.15 and 2.x, with priority coverage for serialization and deserialization CVEs and Spring Data GemFire and Spring Data Geode included, delivered as signed Maven artifacts and Docker images. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a cluster topology and security configuration audit, a WAN replication security review and a GemFire to Geode migration assessment, and Operate adds 24/7 cluster health and memory monitoring with a 15-minute P1 response, a named senior Geode and GemFire engineer, and execution of the GemFire to Geode migration. See GemFire and Geode support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.