Input validation error in Hazelcast - #VU153039
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.
The vulnerability exists due to improper input validation in Hazelcast when handling client requests. A remote attacker can send requests to a cluster member to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.
Memory corruption is possible only in some Enterprise Edition configurations.