Deserialization of Untrusted Data in Hazelcast - #VU153046
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code or disclose information.
The vulnerability exists due to insecure deserialization in JSON/BSON deserialization when processing JSON/BSON data from a client. A remote user can submit crafted JSON/BSON data to instantiate objects insecurely to execute arbitrary code or disclose information.