// OSSeva Blog
SecurityHazelcast Vulnerabilities by Version: CVEs and Advisories for IMDG 3.12, 4.x and Platform 5.x
The short answer
Hazelcast gives each minor release two years of standard support, with patch releases, and then 18 months of extended support with no patches at all. Today only Platform 5.6 and 5.7 are inside standard support, until 15 October 2027 and 13 May 2028. Hazelcast published ten security advisories against Platform in August and September 2026, two of them rated critical. None has a CVE ID yet; each is listed on GitHub under a GHSA identifier. Enterprise 5.6.2 and 5.7.1 fix all ten that apply to them. Enterprise 5.5.10 fixes nine and 5.4.5 fixes five. Community Edition users get fixes only in new minor releases, and 5.7.0 carries five of the nine that affect the Community Edition.
That last point is the one most teams miss. Hazelcast stopped publishing Community Edition patch releases after 5.3.8 in July 2024. Since 5.4, the only Community builds on Maven Central are 5.4.0, 5.5.0, 5.6.0 and 5.7.0, and every patch release on those lines is Enterprise only.
Hazelcast release lines and their advisories
Support dates are from Hazelcast's Version Support Windows article. Enterprise patch dates are from the Hazelcast release notes, except 5.4.5, which is in Hazelcast's Enterprise Maven repository but not in the 5.4 release notes. Each row lists the advisories that name the line and have no fix on it.
| Line | Upstream status | Latest release | Advisories with no fix on this line | Upstream fix on this line |
|---|---|---|---|---|
| Platform 5.7 | Standard support to 13 May 2028 | Enterprise 5.7.1, 13 August 2026; Community 5.7.0, 13 May 2026 | Community 5.7.0: GHSA-jpwr-2cr3-32fm, GHSA-6hfv-j8jg-ggpx, GHSA-74r8-7r86-phxq, GHSA-m4hm-fvgc-9qpm | Enterprise 5.7.1 has all of them; the Community fix waits for the next Community release |
| Platform 5.6 | Standard support to 15 October 2027 | Enterprise 5.6.2, 9 September 2026; Community 5.6.0, 15 October 2025 | Community 5.6.0: the nine 2026 advisories that reach the Community Edition | Enterprise 5.6.1 and 5.6.2; no Community fix on this line |
| Platform 5.5 | Standard support ended 30 July 2026; extended support, without patches, to 30 January 2028 | Enterprise 5.5.10, 16 July 2026; Community 5.5.0 | Enterprise: GHSA-jpwr-2cr3-32fm. Community: nine | Enterprise 5.5.10 for nine of the ten |
| Platform 5.4 | Standard support ended 16 April 2026; extended support to 16 October 2027 | Enterprise 5.4.5; Community 5.4.0 | Enterprise: the five September advisories. Community: nine | Enterprise 5.4.5 for the five advisories that list it |
| Platform 5.3 | Standard support ended 19 May 2025; extended support to 19 November 2026 | 5.3.8, 17 July 2024, the last Community patch release | All ten 2026 advisories | No upstream fix on this line; 5.3.5 has the 2023 fixes |
| Platform 5.0 to 5.2 | Extended support ended: 5.0 on 22 March 2025, 5.1 on 1 September 2025, 5.2 on 24 April 2026 | 5.2.5; 5.1.7; 5.0.5 | All ten 2026 advisories; 5.0 and 5.1 also CVE-2023-45859 and CVE-2023-45860 | No upstream fix on these lines; 5.2.5 has the 2023 fixes |
| IMDG 4.1 and 4.2 | Extended support ended 4 May 2024 and 24 September 2024 | 4.1.10; 4.2.8, 29 May 2023 | CVE-2023-45859, and the 2026 advisories, whose ranges do not exclude 4.x | 4.1.10 and 4.2.6 for CVE-2022-36437 |
| IMDG 4.0 | Extended support ended 4 August 2023 | 4.0.6 | CVE-2022-36437 and CVE-2023-45859 | No upstream fix on this line |
| IMDG 3.12 | Standard and extended support both expired | 3.12.13, 25 August 2022 | CVE-2023-45859 | 3.12.13 for CVE-2022-36437 |
The 2026 advisories give their ranges as every version below the first fixed release, so they do not exclude IMDG 4.x or 3.12. Hazelcast does not say which of them reach those lines and published no fix for them. Each advisory also tells customers who bought an extension beyond standard support to ask Hazelcast Support about patches for older versions, so any such builds are private. For release dates on every line, see the Hazelcast end-of-life chart.
Notable Hazelcast advisories by release line
For the 2026 advisories the score is the CVSS 4.0 score Hazelcast gives on GitHub, because no CVE record exists yet. For the CVEs, the score is NVD's own where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. None of these is in CISA's Known Exploited Vulnerabilities catalogue.
| Advisory | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| GHSA-6v25-8wq6-xq4j | A low-privileged client can read any member's memory and crash members; in some Enterprise configurations it can corrupt memory toward code execution | 9.3 (Hazelcast, CVSS 4.0) | Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 | Enterprise 5.4.5, 5.5.10, 5.6.1, 5.7.0; Community 5.7.0 |
| GHSA-rmqf-mh9c-3gr4 | Clients and members do not validate protocol errors, so a malicious member they are tricked into connecting to can run code on them; on Kubernetes it can also steal service account tokens | 9.2 (Hazelcast, CVSS 4.0) | Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1 | Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0 |
| CVE-2022-36437 | The connection handler lets an unauthenticated attacker act with the identity of another, already authenticated connection | 9.1 (NVD) | 3.12.12 and earlier; 4.0 to 4.0.6; 4.1 to 4.1.9; 4.2 to 4.2.5; 5.0 to 5.0.3; 5.1 to 5.1.2 | 3.12.13, 4.1.10, 4.2.6, 5.0.4, 5.1.3; none for 4.0 |
| CVE-2020-26168 | The IMDG Enterprise LDAP login module accepts invalid passwords in some system-user-dn setups | 9.8 (NVD) | IMDG Enterprise 4.0 to 4.0.2 | 4.0.3 |
| GHSA-w294-6q5q-53p8 | Missing authorization checks in the Predicates API let a malicious client run code on a member | 8.7 (Hazelcast, CVSS 4.0) | Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 | Enterprise 5.4.5, 5.5.10, 5.6.1, 5.7.0; Community 5.7.0 |
| GHSA-wxh9-6gx5-vrjg | Some JSON and BSON deserialization skips the class filter, so a client can instantiate objects it should not | 8.7 (Hazelcast, CVSS 4.0) | Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1 | Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0 |
| CVE-2023-33265 | Executor services do not check client permissions, so an authenticated user can run tasks on members | 8.8 (NVD) | 5.0 to 5.0.4; 5.1 to 5.1.6; 5.2 to 5.2.3 | 5.0.5, 5.1.7, 5.2.4 |
| GHSA-m4hm-fvgc-9qpm | Deserializing data from an IMap can run code when the H2 database library is on the client or member classpath; Management Center is affected too | 8.5 (Hazelcast, CVSS 4.0) | Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0; Management Center before 5.11.1 | Enterprise 5.5.10, 5.6.2, 5.7.1; Management Center 5.11.1; no Community release yet |
| CVE-2016-10750 | The cluster join procedure deserializes a crafted JoinRequest, which can run code if vulnerable classes are on the classpath | 8.1 (NVD) | Before 3.11 | 3.11 |
| CVE-2023-45859 | Some client operations do not check permissions, so authenticated users can reach data they are not allowed to | 7.6 (CISA-ADP) | Through 4.1.10; 4.2 to 4.2.8; 5.0 to 5.0.5; 5.1 to 5.1.7; 5.2.0 to 5.2.4; 5.3.0 to 5.3.4 | 5.2.5, 5.3.5 |
| GHSA-jpwr-2cr3-32fm | Missing validation in Jet lets a malicious client write files to unauthorized locations on a member, sometimes leading to code execution | 7.6 (Hazelcast, CVSS 4.0) | Before 5.6.2; 5.7.0 | Enterprise 5.6.2, 5.7.1; no Community release yet |
| GHSA-p2qm-f9x7-x488 | The experimental Enterprise declarative pipeline for Jet skips job submission permission checks | 7.6 (Hazelcast, CVSS 4.0) | Enterprise before 5.5.10; 5.6.0 to 5.6.1; 5.7.0 | Enterprise 5.5.10, 5.6.2, 5.7.1; Community not affected |
| GHSA-jcpf-8phq-8mmj | Hazelcast SQL skips the class filter on user-supplied expressions, even with SQL disabled | 7.1 (Hazelcast, CVSS 4.0) | Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1 | Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0 |
| GHSA-74r8-7r86-phxq | A bypass of the GHSA-w294-6q5q-53p8 fix that can leak information | 7.1 (Hazelcast, CVSS 4.0) | Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0 | Enterprise 5.5.10, 5.6.2, 5.7.1; no Community release yet |
| CVE-2023-45860 | The SQL mapping for the CSV File Source connector lets clients read files on a member's filesystem | 6.5 (NVD) | 5.1.7 and earlier; 5.2.0 to 5.2.4; 5.3.0 to 5.3.4 | 5.2.5, 5.3.5 |
| GHSA-6hfv-j8jg-ggpx | A malicious client can read any file on a member through Jet functionality, even with Jet disabled | 6.0 (Hazelcast, CVSS 4.0) | Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0 | Enterprise 5.5.10, 5.6.2, 5.7.1; no Community release yet |
Almost every row starts with a client that can already connect to the cluster. A Hazelcast member trusts its clients far more than a database trusts its users: clients send serialized objects, predicates, SQL and Jet jobs that members execute. That is why most of the 2026 list ends in code execution or memory access on a member, and why the advice in the advisories comes down to the same few steps: enforce client authorization where Hazelcast Security is available, keep untrusted clients off the cluster network, and turn off Jet where it is not used. GHSA-rmqf-mh9c-3gr4 runs the other way. It needs a client or member to connect to a malicious member, so restricting egress from clients and members, or requiring TLS between them, reduces the risk until the upgrade.
What each line gets
Platform 5.6 and 5.7
These are the only lines in standard support. Enterprise 5.6.2 and 5.7.1 carry every fix above that applies to them. Community users on 5.7.0 have five of the 2026 fixes and wait for the next Community release for the other four. Community users on 5.6.0 have none, and since Hazelcast has published no Community patch release since 5.3.8, the fix is to move to 5.7.0.
Platform 5.4 and 5.5
Standard support for 5.5 ended on 30 July 2026, two weeks after Enterprise 5.5.10, and for 5.4 on 16 April 2026. Extended support continues to 2027 and 2028 but includes no patch releases. Enterprise 5.5.10 is missing only the Jet path traversal fix, GHSA-jpwr-2cr3-32fm. Enterprise 5.4.5 is missing the five September advisories. Community 5.4.0 and 5.5.0 have none of the 2026 fixes.
Platform 5.0 to 5.3
5.3.8, from July 2024, was the last Community patch release Hazelcast published, which is why many estates stopped there. It carries the 2023 fixes for CVE-2023-45859 and CVE-2023-45860 in 5.3.5, but none of the 2026 fixes. 5.2.5, 5.1.7 and 5.0.5 are older still, and 5.0 and 5.1 never got the fix for CVE-2023-45859.
IMDG 4.x
4.2.8 and 4.1.10 carry the CVE-2022-36437 fix but not the fix for CVE-2023-45859, which lists every release through 4.2.8. IMDG 4.0 has neither, so 4.0.6 is still exposed to the unauthenticated connection hijack in CVE-2022-36437. In 5.0, IMDG and Jet were merged into one Platform distribution with new artifact coordinates, so moving from 4.x is a dependency change for every application as well as a cluster upgrade.
IMDG 3.12
3.12.13 fixed CVE-2022-36437, but nothing has been released for 3.12 since August 2022. 3.12 has the java-serialization-filter setting that 3.11 added for CVE-2016-10750, but it is off by default. Hazelcast's migration documentation says there is no in-place or rolling upgrade from 3.12 to Platform 5, because both the member and client protocols changed; see migrating Hazelcast IMDG 3.x to Platform 5.
What to do on each line
- Enterprise 5.6 and 5.7. Move to 5.6.2 or 5.7.1 now, and upgrade Management Center to 5.11.1.
- Community 5.x. Move to 5.7.0, which fixes the two critical advisories. Until the next Community release, keep the H2 library off client and member classpaths, restrict cluster access to trusted clients, and disable Jet if you do not use it.
- Enterprise 5.4 and 5.5. Take 5.4.5 or 5.5.10, then plan the move to 5.6 or 5.7, since no more patch releases will come for either line.
- IMDG 3.12 and 4.x. Plan the migration to Platform 5.7, or take patched builds from a supplier that backports fixes. Until then, enable the Java serialization filter with an allowlist, keep member and client ports off untrusted networks, and on Enterprise clusters give each application its own client credentials and permissions.
Where OSSeva fits
OSSeva ships patched builds of Hazelcast IMDG 3.12, 4.0 and 4.2 and Platform 5.3 and 5.5, with client libraries patched in step with member builds and priority coverage for deserialization and cluster protocol advisories, delivered as signed Maven artifacts and Docker images. OSSeva backports fixes of this class to the end-of-life release lines it patches, with no Hazelcast subscription required. They are available now on the Patch, Assure and Operate tiers. Assure adds a member port exposure and join mechanism audit, a serialization configuration and class filtering review, and an assessment of the upgrade or migration options, and Operate adds 24/7 heap, partition and member health monitoring with a 15-minute P1 response and a named senior data grid engineer. See Hazelcast support and Hazelcast IMDG extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.