Back to blog

// OSSeva Blog

Security

Hazelcast Vulnerabilities by Version: CVEs and Advisories for IMDG 3.12, 4.x and Platform 5.x

Matt Reynolds9 min read

The short answer

Hazelcast gives each minor release two years of standard support, with patch releases, and then 18 months of extended support with no patches at all. Today only Platform 5.6 and 5.7 are inside standard support, until 15 October 2027 and 13 May 2028. Hazelcast published ten security advisories against Platform in August and September 2026, two of them rated critical. None has a CVE ID yet; each is listed on GitHub under a GHSA identifier. Enterprise 5.6.2 and 5.7.1 fix all ten that apply to them. Enterprise 5.5.10 fixes nine and 5.4.5 fixes five. Community Edition users get fixes only in new minor releases, and 5.7.0 carries five of the nine that affect the Community Edition.

That last point is the one most teams miss. Hazelcast stopped publishing Community Edition patch releases after 5.3.8 in July 2024. Since 5.4, the only Community builds on Maven Central are 5.4.0, 5.5.0, 5.6.0 and 5.7.0, and every patch release on those lines is Enterprise only.

Hazelcast release lines and their advisories

Support dates are from Hazelcast's Version Support Windows article. Enterprise patch dates are from the Hazelcast release notes, except 5.4.5, which is in Hazelcast's Enterprise Maven repository but not in the 5.4 release notes. Each row lists the advisories that name the line and have no fix on it.

LineUpstream statusLatest releaseAdvisories with no fix on this lineUpstream fix on this line
Platform 5.7Standard support to 13 May 2028Enterprise 5.7.1, 13 August 2026; Community 5.7.0, 13 May 2026Community 5.7.0: GHSA-jpwr-2cr3-32fm, GHSA-6hfv-j8jg-ggpx, GHSA-74r8-7r86-phxq, GHSA-m4hm-fvgc-9qpmEnterprise 5.7.1 has all of them; the Community fix waits for the next Community release
Platform 5.6Standard support to 15 October 2027Enterprise 5.6.2, 9 September 2026; Community 5.6.0, 15 October 2025Community 5.6.0: the nine 2026 advisories that reach the Community EditionEnterprise 5.6.1 and 5.6.2; no Community fix on this line
Platform 5.5Standard support ended 30 July 2026; extended support, without patches, to 30 January 2028Enterprise 5.5.10, 16 July 2026; Community 5.5.0Enterprise: GHSA-jpwr-2cr3-32fm. Community: nineEnterprise 5.5.10 for nine of the ten
Platform 5.4Standard support ended 16 April 2026; extended support to 16 October 2027Enterprise 5.4.5; Community 5.4.0Enterprise: the five September advisories. Community: nineEnterprise 5.4.5 for the five advisories that list it
Platform 5.3Standard support ended 19 May 2025; extended support to 19 November 20265.3.8, 17 July 2024, the last Community patch releaseAll ten 2026 advisoriesNo upstream fix on this line; 5.3.5 has the 2023 fixes
Platform 5.0 to 5.2Extended support ended: 5.0 on 22 March 2025, 5.1 on 1 September 2025, 5.2 on 24 April 20265.2.5; 5.1.7; 5.0.5All ten 2026 advisories; 5.0 and 5.1 also CVE-2023-45859 and CVE-2023-45860No upstream fix on these lines; 5.2.5 has the 2023 fixes
IMDG 4.1 and 4.2Extended support ended 4 May 2024 and 24 September 20244.1.10; 4.2.8, 29 May 2023CVE-2023-45859, and the 2026 advisories, whose ranges do not exclude 4.x4.1.10 and 4.2.6 for CVE-2022-36437
IMDG 4.0Extended support ended 4 August 20234.0.6CVE-2022-36437 and CVE-2023-45859No upstream fix on this line
IMDG 3.12Standard and extended support both expired3.12.13, 25 August 2022CVE-2023-458593.12.13 for CVE-2022-36437

The 2026 advisories give their ranges as every version below the first fixed release, so they do not exclude IMDG 4.x or 3.12. Hazelcast does not say which of them reach those lines and published no fix for them. Each advisory also tells customers who bought an extension beyond standard support to ask Hazelcast Support about patches for older versions, so any such builds are private. For release dates on every line, see the Hazelcast end-of-life chart.

Notable Hazelcast advisories by release line

For the 2026 advisories the score is the CVSS 4.0 score Hazelcast gives on GitHub, because no CVE record exists yet. For the CVEs, the score is NVD's own where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. None of these is in CISA's Known Exploited Vulnerabilities catalogue.

AdvisoryIssueCVSSAffectedFixed in
GHSA-6v25-8wq6-xq4jA low-privileged client can read any member's memory and crash members; in some Enterprise configurations it can corrupt memory toward code execution9.3 (Hazelcast, CVSS 4.0)Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0Enterprise 5.4.5, 5.5.10, 5.6.1, 5.7.0; Community 5.7.0
GHSA-rmqf-mh9c-3gr4Clients and members do not validate protocol errors, so a malicious member they are tricked into connecting to can run code on them; on Kubernetes it can also steal service account tokens9.2 (Hazelcast, CVSS 4.0)Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0
CVE-2022-36437The connection handler lets an unauthenticated attacker act with the identity of another, already authenticated connection9.1 (NVD)3.12.12 and earlier; 4.0 to 4.0.6; 4.1 to 4.1.9; 4.2 to 4.2.5; 5.0 to 5.0.3; 5.1 to 5.1.23.12.13, 4.1.10, 4.2.6, 5.0.4, 5.1.3; none for 4.0
CVE-2020-26168The IMDG Enterprise LDAP login module accepts invalid passwords in some system-user-dn setups9.8 (NVD)IMDG Enterprise 4.0 to 4.0.24.0.3
GHSA-w294-6q5q-53p8Missing authorization checks in the Predicates API let a malicious client run code on a member8.7 (Hazelcast, CVSS 4.0)Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0Enterprise 5.4.5, 5.5.10, 5.6.1, 5.7.0; Community 5.7.0
GHSA-wxh9-6gx5-vrjgSome JSON and BSON deserialization skips the class filter, so a client can instantiate objects it should not8.7 (Hazelcast, CVSS 4.0)Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0
CVE-2023-33265Executor services do not check client permissions, so an authenticated user can run tasks on members8.8 (NVD)5.0 to 5.0.4; 5.1 to 5.1.6; 5.2 to 5.2.35.0.5, 5.1.7, 5.2.4
GHSA-m4hm-fvgc-9qpmDeserializing data from an IMap can run code when the H2 database library is on the client or member classpath; Management Center is affected too8.5 (Hazelcast, CVSS 4.0)Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0; Management Center before 5.11.1Enterprise 5.5.10, 5.6.2, 5.7.1; Management Center 5.11.1; no Community release yet
CVE-2016-10750The cluster join procedure deserializes a crafted JoinRequest, which can run code if vulnerable classes are on the classpath8.1 (NVD)Before 3.113.11
CVE-2023-45859Some client operations do not check permissions, so authenticated users can reach data they are not allowed to7.6 (CISA-ADP)Through 4.1.10; 4.2 to 4.2.8; 5.0 to 5.0.5; 5.1 to 5.1.7; 5.2.0 to 5.2.4; 5.3.0 to 5.3.45.2.5, 5.3.5
GHSA-jpwr-2cr3-32fmMissing validation in Jet lets a malicious client write files to unauthorized locations on a member, sometimes leading to code execution7.6 (Hazelcast, CVSS 4.0)Before 5.6.2; 5.7.0Enterprise 5.6.2, 5.7.1; no Community release yet
GHSA-p2qm-f9x7-x488The experimental Enterprise declarative pipeline for Jet skips job submission permission checks7.6 (Hazelcast, CVSS 4.0)Enterprise before 5.5.10; 5.6.0 to 5.6.1; 5.7.0Enterprise 5.5.10, 5.6.2, 5.7.1; Community not affected
GHSA-jcpf-8phq-8mmjHazelcast SQL skips the class filter on user-supplied expressions, even with SQL disabled7.1 (Hazelcast, CVSS 4.0)Before 5.4.5; 5.5.0 to 5.5.9; 5.6.0 to 5.6.1Enterprise 5.4.5, 5.5.10, 5.6.2, 5.7.0; Community 5.7.0
GHSA-74r8-7r86-phxqA bypass of the GHSA-w294-6q5q-53p8 fix that can leak information7.1 (Hazelcast, CVSS 4.0)Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0Enterprise 5.5.10, 5.6.2, 5.7.1; no Community release yet
CVE-2023-45860The SQL mapping for the CSV File Source connector lets clients read files on a member's filesystem6.5 (NVD)5.1.7 and earlier; 5.2.0 to 5.2.4; 5.3.0 to 5.3.45.2.5, 5.3.5
GHSA-6hfv-j8jg-ggpxA malicious client can read any file on a member through Jet functionality, even with Jet disabled6.0 (Hazelcast, CVSS 4.0)Before 5.5.10; 5.6.0 to 5.6.1; 5.7.0Enterprise 5.5.10, 5.6.2, 5.7.1; no Community release yet

Almost every row starts with a client that can already connect to the cluster. A Hazelcast member trusts its clients far more than a database trusts its users: clients send serialized objects, predicates, SQL and Jet jobs that members execute. That is why most of the 2026 list ends in code execution or memory access on a member, and why the advice in the advisories comes down to the same few steps: enforce client authorization where Hazelcast Security is available, keep untrusted clients off the cluster network, and turn off Jet where it is not used. GHSA-rmqf-mh9c-3gr4 runs the other way. It needs a client or member to connect to a malicious member, so restricting egress from clients and members, or requiring TLS between them, reduces the risk until the upgrade.

What each line gets

Platform 5.6 and 5.7

These are the only lines in standard support. Enterprise 5.6.2 and 5.7.1 carry every fix above that applies to them. Community users on 5.7.0 have five of the 2026 fixes and wait for the next Community release for the other four. Community users on 5.6.0 have none, and since Hazelcast has published no Community patch release since 5.3.8, the fix is to move to 5.7.0.

Platform 5.4 and 5.5

Standard support for 5.5 ended on 30 July 2026, two weeks after Enterprise 5.5.10, and for 5.4 on 16 April 2026. Extended support continues to 2027 and 2028 but includes no patch releases. Enterprise 5.5.10 is missing only the Jet path traversal fix, GHSA-jpwr-2cr3-32fm. Enterprise 5.4.5 is missing the five September advisories. Community 5.4.0 and 5.5.0 have none of the 2026 fixes.

Platform 5.0 to 5.3

5.3.8, from July 2024, was the last Community patch release Hazelcast published, which is why many estates stopped there. It carries the 2023 fixes for CVE-2023-45859 and CVE-2023-45860 in 5.3.5, but none of the 2026 fixes. 5.2.5, 5.1.7 and 5.0.5 are older still, and 5.0 and 5.1 never got the fix for CVE-2023-45859.

IMDG 4.x

4.2.8 and 4.1.10 carry the CVE-2022-36437 fix but not the fix for CVE-2023-45859, which lists every release through 4.2.8. IMDG 4.0 has neither, so 4.0.6 is still exposed to the unauthenticated connection hijack in CVE-2022-36437. In 5.0, IMDG and Jet were merged into one Platform distribution with new artifact coordinates, so moving from 4.x is a dependency change for every application as well as a cluster upgrade.

IMDG 3.12

3.12.13 fixed CVE-2022-36437, but nothing has been released for 3.12 since August 2022. 3.12 has the java-serialization-filter setting that 3.11 added for CVE-2016-10750, but it is off by default. Hazelcast's migration documentation says there is no in-place or rolling upgrade from 3.12 to Platform 5, because both the member and client protocols changed; see migrating Hazelcast IMDG 3.x to Platform 5.

What to do on each line

  • Enterprise 5.6 and 5.7. Move to 5.6.2 or 5.7.1 now, and upgrade Management Center to 5.11.1.
  • Community 5.x. Move to 5.7.0, which fixes the two critical advisories. Until the next Community release, keep the H2 library off client and member classpaths, restrict cluster access to trusted clients, and disable Jet if you do not use it.
  • Enterprise 5.4 and 5.5. Take 5.4.5 or 5.5.10, then plan the move to 5.6 or 5.7, since no more patch releases will come for either line.
  • IMDG 3.12 and 4.x. Plan the migration to Platform 5.7, or take patched builds from a supplier that backports fixes. Until then, enable the Java serialization filter with an allowlist, keep member and client ports off untrusted networks, and on Enterprise clusters give each application its own client credentials and permissions.

Where OSSeva fits

OSSeva ships patched builds of Hazelcast IMDG 3.12, 4.0 and 4.2 and Platform 5.3 and 5.5, with client libraries patched in step with member builds and priority coverage for deserialization and cluster protocol advisories, delivered as signed Maven artifacts and Docker images. OSSeva backports fixes of this class to the end-of-life release lines it patches, with no Hazelcast subscription required. They are available now on the Patch, Assure and Operate tiers. Assure adds a member port exposure and join mechanism audit, a serialization configuration and class filtering review, and an assessment of the upgrade or migration options, and Operate adds 24/7 heap, partition and member health monitoring with a 15-minute P1 response and a named senior data grid engineer. See Hazelcast support and Hazelcast IMDG extended support.

Tags

HazelcastCVEHazelcast IMDGHazelcast Platform 5End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.