{"id":"CVE-2016-10750","details":"In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.","aliases":["GHSA-jv65-pf7v-f7p8"],"modified":"2026-07-08T12:43:10.086681Z","published":"2019-05-22T14:29:00.223Z","references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2413"},{"type":"REPORT","url":"https://github.com/hazelcast/hazelcast/issues/8024"},{"type":"REPORT","url":"https://github.com/hazelcast/hazelcast/pull/12230"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hazelcast/hazelcast","events":[{"introduced":"0"},{"fixed":"7806a22c9f9309c0669286197b872113323d3c1d"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.11"}]}}],"versions":["v3.11","v3.5.1-stale","v3.3-EA2","v3.3-EA","v3.2","v3.1","v3.0","v3.0-RC1","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10750.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}