Back to blog

// OSSeva Blog

Security

GemFire and Geode Vulnerabilities by Version: CVEs for Tanzu GemFire 9.x and 10.x and Apache Geode 1.x and 2.x

Matt Reynolds9 min read

The short answer

Broadcom supports three GemFire lines: 10.1 until 28 February 2027, 10.2 until 31 October 2028 and 10.3 until 31 July 2029. General support for 10.0 ended on 30 April 2026 and for 9.15 on 31 October 2025, and their last patches were 10.0.8 and 9.15.16. On the open source side, the Apache Geode project voted in March 2026 to support only 2.0.x and 1.15.x and to declare 1.14.x and every earlier line end of life, with no further bug fixes, security fixes or backports. Geode's own CVEs since 2022 are fixed only from 1.15, so a cluster on 1.14 or older is missing them and will get no fix.

The two products now get most of their security fixes the same way: as updates to the libraries they bundle. Broadcom's advisory for GemFire 10.3.2, published on 2 October 2026, lists 36 resolved vulnerabilities, and Geode 2.0.3 in September 2026 updated Shiro, Jetty, Jackson, Bouncy Castle and Log4j among others. A line that stops getting releases stops getting those updates too.

GemFire and Geode release lines and their CVEs

GemFire dates are from Broadcom's product lifecycle table and the GemFire release notes. Geode dates and support status are from the Apache release records, the Geode release announcements and the result of the Geode support vote on 11 March 2026.

LineUpstream statusLatest releaseNotable CVEsUpstream fix on this line
GemFire 10.3General support to 31 July 2029; JDK 17 minimum10.3.2, 22 September 202636 vulnerabilities in Broadcom's 10.3.2 advisory, led by CVE-2026-71290 in the bundled HttpComponents Client10.3.2
GemFire 10.2General support to 31 October 202810.2.8, 22 September 2026Broadcom's 10.2.8 advisory, also rated critical10.2.8
GemFire 10.1General support to 28 February 202710.1.9, 18 August 2026Bundled-library fixes such as CVE-2025-67735 in Netty, fixed in 10.1.610.1.9; further 10.1 patches until February 2027
GemFire 10.0General support ended 30 April 202610.0.8, 17 March 2026Fixes shipped in 10.1.8, 10.1.9 and later releasesNo upstream fix on this line
GemFire 9.15General support ended 31 October 20259.15.16, 8 July 2025Every fix Broadcom has shipped since July 2025No upstream fix on this line; 9.15.3 fixed CVE-2022-34870
GemFire 9.10 and older9.10 general support ended 31 December 20249.10.17, 3 November 2022CVE-2019-11286 and CVE-2020-5396 before 9.10.0No upstream fix on these lines
Geode 2.0Supported; current major line, Java 17 and Jakarta EE 102.0.3, September 2026Bundled-library fixes, including CVE-2026-49268 in Shiro2.0.3
Geode 1.15Supported; final 1.x line1.15.5, September 2026CVE-2025-47410 and CVE-2024-44088 before 1.15.21.15.2 to 1.15.5
Geode 1.14End of life by PMC vote, 11 March 20261.14.4, March 2022CVE-2025-47410, CVE-2024-44088, CVE-2022-37023, CVE-2022-34870; CVE-2022-37021 on 1.14.0No upstream fix on this line
Geode 1.13 and 1.12End of life1.13.8; 1.12.9, June 2022The 1.14 list, plus CVE-2022-37021 and CVE-2022-37022 on the earlier patch releasesNo upstream fix on these lines

The releases page on geode.apache.org lists nothing after 2.0.0 and 1.15.2, so the newer releases are recorded in the dev list announcements and the Apache release archive. GemFire shares its code base with Geode, and Broadcom lists some Geode CVEs in its release notes: 9.15.3 fixed CVE-2022-34870. The GemFire notes do not list CVE-2024-44088 or CVE-2025-47410, so whether a given GemFire build is exposed to them is a question for Broadcom. For every date in one place, see the GemFire and Geode end-of-life tracker.

Notable GemFire and Geode CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2022-37021JMX over RMI on Java 8 deserializes untrusted data9.8 (NVD)Geode 1.12.5 and earlier; 1.13.0 to 1.13.4; 1.14.0Geode 1.15.0 on Java 11, or on Java 8 with -Dgeode.enableGlobalSerialFilter=true
CVE-2017-15692The locator's TcpServer deserializes data from its network port, which can run code if certain classes are on the classpath9.8 (NVD)Geode before 1.4.0Geode 1.4.0
CVE-2019-11286A JMX service on the network does not restrict input, so an authenticated user with crafted credentials can run code9.1 (NVD)GemFire before 9.7.5; 9.8.0 to 9.8.4; 9.9.0GemFire 9.7.5, 9.8.5, 9.9.1, 9.10.0
CVE-2020-5396Without a SecurityManager, the JMX service lets a user create an MLet MBean and run code8.8 (NVD)GemFire before 9.7.6; 9.8.0 to 9.8.6; 9.9.0 to 9.9.1GemFire 9.7.6, 9.8.7, 9.9.2, 9.10.0
CVE-2025-47410GET requests to the Management and Monitoring REST API are open to CSRF, so a tricked user's session can run gfsh commands8.8 (CISA-ADP)Geode 1.10.0 to 1.15.1Geode 1.15.2
CVE-2022-37022JMX over RMI on Java 11 deserializes untrusted data8.8 (NVD)Geode 1.12.2 and earlier; 1.13.0 to 1.13.2Geode 1.15.0
CVE-2021-34797Log redaction misses passwords and security properties that start with a character other than a letter or digit7.5 (NVD)Geode 1.12.4 and earlier; 1.13.0 to 1.13.4Geode 1.12.5, 1.13.5, 1.14.0
CVE-2022-37023The REST API deserializes untrusted data on Java 8 and Java 116.5 (NVD)Geode before 1.15.0Geode 1.15.0, with validate-serializable-objects=true
CVE-2024-44088Reflected cross-site scripting in the REST web API can lead to session theft6.1 (CISA-ADP)Geode 1.1.0 to 1.15.1Geode 1.15.2
CVE-2022-34870Stored cross-site scripting through region entries viewed in the Pulse web application5.4 (NVD)Geode 1.15.0 and earlierGeode 1.15.1; GemFire 9.15.3

The serious rows share one shape. GemFire and Geode expose JMX, a locator port and REST endpoints, and every remote code execution above goes through one of them, mostly by way of Java deserialization. Since 1.15 the fixes depend on configuration as much as on the release: CVE-2022-37021 needs Java 11, or the global serial filter on Java 8, and CVE-2022-37023 needs validate-serializable-objects set to true, which is off by default. The newer CVE-2025-47410 and CVE-2024-44088 matter wherever the Management and Monitoring REST API or the developer REST API is reachable from a browser, because both work by tricking a logged-in user.

The bundled libraries carry most of the recent volume. CVE-2026-71290, scored 9.1 by CISA-ADP, is a hostname verification flaw in the async client of Apache HttpComponents Client 5.4 and later, fixed in GemFire 10.3.2. Geode 1.15.3 addressed CVE-2025-48924 in Commons Lang and a resource exhaustion issue, and Geode 2.0.3 updated Shiro from 2.1.0 to 3.0.0 for CVE-2026-49268.

What each line gets

GemFire 10.2 and 10.3

Both are supported for years yet, and 10.2.8 and 10.3.2 are the current patches. 10.3 needs JDK 17 and moves to Jakarta EE, so 10.2 is the line for clusters that cannot change their JDK or their application libraries yet. Both accept a direct upgrade from any 10.x release.

GemFire 10.1 and 10.0

10.1 is still patched, most recently 10.1.9 in August 2026, but its support ends on 28 February 2027. 10.0 stopped at 10.0.8 in March 2026 and does not have the 10.1.8 changes that limit queued connections on servers and locators to resist resource exhaustion. Moving to 10.2 or 10.3 is a direct upgrade from either. See GemFire 10.0 end of life.

GemFire 9.15 and older

9.15.16, from July 2025, was the last 9.x patch. The release notes require a 9.x cluster to pass through 10.1 before 10.2 or 10.3, and a cluster on 9.15.13 or later must land on 10.1.2 or later. CVE-2019-11286 and CVE-2020-5396 matter only to clusters on 9.9 or earlier without the patch releases that fixed them. See GemFire 9.15 end of life and upgrading GemFire 9.15 and 10.0 to 10.2 or 10.3.

Geode 2.0 and 1.15

These are the two lines the Geode project supports. 1.15.2 fixed the two 2025 CVEs. 1.15.3 and 1.15.4 in 2026 added security and dependency updates and 1.15.5 bug fixes, and each of those announcements points users to the latest 2.0.x release. Geode 2.0 needs Java 17 and moves to Jakarta EE 10, so it is a bigger step than a patch upgrade.

Geode 1.14 and older

The March 2026 vote ended all support for these lines. 1.14.4, from 2022, lacks the 2025 CSRF and cross-site scripting fixes and the 1.15 deserialization controls, and 1.12 and 1.13 also lack the JMX over RMI fixes. The supported path is 1.14 to 1.15 within 1.x, then 1.15 to 2.0.

What to do on each line

  • GemFire 10.2 and 10.3. Take 10.2.8 or 10.3.2, and subscribe to Broadcom's Tanzu security advisories, which is where the per-release vulnerability lists appear.
  • GemFire 10.0 and 10.1. Move to 10.2 or 10.3 before 10.1 support ends in February 2027.
  • GemFire 9.x. Plan the two-step upgrade through 10.1, the move to Apache Geode, or patched builds from a supplier that backports fixes. Until then, run with a SecurityManager, keep JMX, locator and REST ports off untrusted networks, and keep Pulse and the REST APIs away from browsers on shared networks.
  • Geode 1.14 and older. Move to 1.15.5, then plan 2.0. On 1.15, set validate-serializable-objects=true with a serializable-object-filter, and on Java 8 start locators and servers with -Dgeode.enableGlobalSerialFilter=true.

For teams weighing a move off the commercial product, see moving from Tanzu GemFire to Apache Geode and the open source paths off VMware Tanzu products.

Where OSSeva fits

OSSeva ships patched builds for GemFire 9.x and 10.x and Apache Geode 1.14, 1.15 and 2.x, with priority coverage for serialization and deserialization CVEs and Spring Data GemFire and Spring Data Geode included, delivered as signed Maven artifacts and Docker images. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a cluster topology and security configuration audit, a WAN replication security review and a GemFire to Geode migration assessment, and Operate adds 24/7 cluster health and memory monitoring with a 15-minute P1 response, a named senior Geode and GemFire engineer, and execution of the GemFire to Geode migration. See GemFire and Geode support.

Tags

GemFireApache GeodeCVETanzu GemFireEnd of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.