hazelcast 5.10.3 Helm chart
wenermeScored 15 Sept 2026
Hazelcast is a streaming and memory-first application platform for fast, stateful, data-intensive workloads on-premises, at the edge or as a fully managed cloud service.
Version 5.10.3 yesterdayapp version 5.5.0 0Artifact Hub
hazelcast 5.10.3 deploys 2 container images: hazelcast/management-center and hazelcast/hazelcast. Across them, 201 findings — 1 critical, 3 high. The highest contribution is GHSA-2c59-37c4-qrx5 in parquet-avro 1.14.1, fixed in 1.15.1. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| hazelcast/ | 5.5.2 | 011155 | 795 |
| hazelcast/ | 5.5.0 | 123695 | 1,828 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-wwpq-f5c3-7hvx | spring-boot | no fix listed |
| Low | GHSA-7p3p-8qv8-m2vh | jetty-server | 12.0.35 |
| Low | GHSA-gcjf-9mgh-3p7g | netty-codec-http | 4.1.136.Final |
| Low | GHSA-v8h7-rr48-vmmv | netty-codec-http | 4.1.133.Final |
| Low | GHSA-wc96-39fc-566f | netty-handler-ssl-ocsp | 4.1.136.Final |
| Low | GHSA-563q-j3cm-6jxm | netty-codec-http2 | 4.1.135.Final |
| Low | GHSA-5x3r-wrvg-rp6q | netty-codec-http2 | 4.1.135.Final |
| Low | ALPINE-CVE-2024-13176 | openssl | 3.3.2-r2 |
| Low | GHSA-293q-567p-wmwq | spring-security-web | no fix listed |
| Low | GHSA-q3v6-hm2v-pw99 | spring-security-core | 6.3.5 |
| Low | ALPINE-CVE-2026-27171 | zlib | 1.3.2-r0 |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.1.135.Final |
| Low | ALPINE-CVE-2025-5025 | curl | 8.14.0-r0 |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | no fix listed |
| Low | GHSA-cvc6-q2cp-2xhw | spring-security-oauth2-jose | no fix listed |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | no fix listed |
| Low | ALPINE-CVE-2025-0167 | curl | 8.12.0-r0 |
| Low | ALPINE-CVE-2026-6042 | musl | 1.2.5-r2 |
| Low | ALPINE-CVE-2026-22795 | openssl | 3.3.6-r0 |
| Low | GHSA-7fch-4f2f-jcgm | spring-websocket | no fix listed |
| Low | GHSA-wh89-7897-x99h | netty-codec-haproxy | 4.1.136.Final |
| Low | GHSA-q723-847q-5g8g | spring-websocket | no fix listed |
| Low | ALPINE-CVE-2025-68160 | openssl | 3.3.6-r0 |
| Low | GHSA-659m-px2c-25wj | spring-core | no fix listed |
| Low | GHSA-ggg2-9786-hwc8 | spring-boot-autoconfigure | no fix listed |
| Low | GHSA-4wp7-92pw-q264 | spring-context | 6.1.20 |
| Low | GHSA-vxf7-qj7q-83fh | spring-security-core | no fix listed |
| Low | GHSA-h3qp-gqrc-q736 | spring-webmvc | no fix listed |
| Low | GHSA-9f52-rjqv-25qv | spring-expression | no fix listed |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-kqueue | 4.1.135.Final |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-epoll | 4.1.135.Final |
| Low | GHSA-wjpw-4j6x-6rwh | jetty-http | 12.0.31 |
| Low | ALPINE-CVE-2025-69418 | openssl | 3.3.6-r0 |
| Low | GHSA-wg35-8jpf-2xv3 | spring-webmvc | no fix listed |
| Low | ALPINE-CVE-2025-46394 | busybox | 1.36.1-r31 |
| Low | GHSA-fghv-69vj-qj49 | netty-codec-http | 4.1.125.Final |
| Low | ALPINE-CVE-2024-58251 | busybox | 1.36.1-r31 |
| Low | GHSA-6hcq-hmm3-jj3c | spring-webmvc | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 5.10.3latest | yesterday | 5.5.0 | 1347150 | 2,623 |
| 5.10.2 | 1 year ago | 5.5.0 | 1346154 | 2,634 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.