Deserialization of Untrusted Data in Hazelcast - #VU153044
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in IMap client deserialization when deserializing malicious data from an IMap. A remote user can place malicious data in an IMap to execute arbitrary code.
The H2 database library must be on the classpath of the client or member application.