Known Vulnerabilities for products from Hazelcast
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Hazelcast".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43865 json | Not Provided | 2026-07-06 | 2026-07-06 | |
| CVE-2023-33265 json | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions proper... | 8.8 - HIGH | 2023-07-18 | 2023-07-28 |
| CVE-2023-33264 json | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the memb... | 4.3 - MEDIUM | 2023-05-22 | 2023-06-02 |
| CVE-2022-36437 json | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data ... | 9.1 - CRITICAL | 2022-12-29 | 2023-01-09 |
| CVE-2022-0265 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-03-03 | 2022-04-29 |
| CVE-2020-26168 json | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x throu... | 9.8 - CRITICAL | 2020-11-09 | 2020-11-18 |
| CVE-2016-10750 json | In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an a... | 8.1 - HIGH | 2019-05-22 | 2019-08-08 |
Known software with vulnerabilities from Hazelcast
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Hazelcast | Hazelcast | 1.9.3 |