Input validation error in Hazelcast - #VU153039

 

Input validation error in Hazelcast - #VU153039

Published: October 1, 2026


Vulnerability identifier: #VU153039
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.

The vulnerability exists due to improper input validation in Hazelcast when handling client requests. A remote attacker can send requests to a cluster member to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.

Memory corruption is possible only in some Enterprise Edition configurations.


Affected software

Hazelcast

Remediation

Install security update from vendor's website.

Hazelcast - addressed in versions 5.4.5, 5.5.10, 5.6.1, 5.7.0

External References

Related Security Bulletins