StackRadar

hazelcast 5.10.4 Helm chart

wenerme

Scored 6 Oct 2026

Hazelcast is a streaming and memory-first application platform for fast, stateful, data-intensive workloads on-premises, at the edge or as a fully managed cloud service.

Version 5.10.4 todayapp version 5.5.0 0Artifact Hub

hazelcast 5.10.4 deploys 2 container images: hazelcast/management-center and hazelcast/hazelcast. Across them, 220 findings — 2 critical, 2 high. The highest contribution is GHSA-2c59-37c4-qrx5 in parquet-avro 1.14.1, fixed in 1.15.1. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.

Radar Score

2,9722262154

220 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
hazelcast/management-center5.5.2011561943
hazelcast/hazelcast5.5.02147932,029

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

196 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-8c42-7qj2-3j46netty-codec-http@4.1.111.Final4.1.137.Final
LowGHSA-x2r2-rvhq-2mqvspring-security-web@6.3.3no fix listed
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.17.22.18.9
LowGHSA-389x-839f-4rhxnetty-common@4.1.111.Final4.1.118.Final
LowGHSA-293q-567p-wmwqspring-security-web@6.3.3no fix listed
LowGHSA-hvcg-qmg6-jm4cnetty-codec-http@4.1.111.Final4.1.135.Final
LowGHSA-mfg7-5gfp-c4w3netty-codec-dns@4.1.111.Final4.1.136.Final
LowGHSA-rgrr-p7gp-5xj7netty-codec-redis@4.1.111.Final4.1.133.Final
LowGHSA-hgj6-7826-r7m5jackson-databind@2.17.22.18.8
LowALPINE-CVE-2024-11053curl@8.9.0-r08.11.1-r0
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@6.1.12no fix listed
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.111.Final4.1.133.Final
LowGHSA-957g-f97v-vppcspring-webmvc@6.1.12no fix listed
LowGHSA-w7x5-g22v-xqhrjetty-util@12.0.1212.0.35
LowGHSA-vvgp-rfg2-7rr6jackson-databind@2.17.22.18.9
LowGHSA-7p3p-8qv8-m2vhjetty-server@12.0.1212.0.35
LowGHSA-cjpg-rgq5-fr37spring-webmvc@6.1.12no fix listed
LowGHSA-wwpq-f5c3-7hvxspring-boot@3.3.3no fix listed
LowALPINE-CVE-2024-13176openssl@3.3.1-r33.3.2-r2
LowGHSA-q3v6-hm2v-pw99spring-security-core@6.3.36.3.5
LowGHSA-q723-847q-5g8gspring-websocket@6.1.12no fix listed
LowALPINE-CVE-2025-5025curl@8.9.0-r08.14.0-r0
LowALPINE-CVE-2026-27171zlib@1.3.1-r11.3.2-r0
LowGHSA-cvc6-q2cp-2xhwspring-security-oauth2-jose@6.3.3no fix listed
LowALPINE-CVE-2026-22795openssl@3.3.1-r33.3.6-r0
LowGHSA-wh89-7897-x99hnetty-codec-haproxy@4.1.111.Final4.1.136.Final
LowALPINE-CVE-2025-0167curl@8.9.0-r08.12.0-r0
LowGHSA-7fch-4f2f-jcgmspring-websocket@6.1.12no fix listed
LowGHSA-659m-px2c-25wjspring-core@6.1.12no fix listed
LowGHSA-5q95-hrpc-m3w3jline-reader@3.26.23.30.15
LowGHSA-ggg2-9786-hwc8spring-boot-autoconfigure@3.3.3no fix listed
LowALPINE-CVE-2025-68160openssl@3.3.1-r33.3.6-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r01.2.5-r2
LowGHSA-h3qp-gqrc-q736spring-webmvc@6.1.12no fix listed
LowGHSA-9f52-rjqv-25qvspring-expression@6.1.12no fix listed
LowGHSA-4wp7-92pw-q264spring-context@6.1.126.1.20
LowGHSA-w573-9ffj-6ff9netty-transport-native-kqueue@4.1.111.Final4.1.135.Final
LowGHSA-w573-9ffj-6ff9netty-transport-native-epoll@4.1.111.Final4.1.135.Final
LowGHSA-vxf7-qj7q-83fhspring-security-core@6.3.3no fix listed
LowALPINE-CVE-2025-69418openssl@3.3.1-r33.3.6-r0
LowGHSA-wjpw-4j6x-6rwhjetty-http@12.0.1212.0.31
LowGHSA-wg35-8jpf-2xv3spring-webmvc@6.1.12no fix listed
LowALPINE-CVE-2025-46394busybox@1.36.1-r291.36.1-r31
LowGHSA-fghv-69vj-qj49netty-codec-http@4.1.111.Final4.1.125.Final
LowALPINE-CVE-2024-58251busybox@1.36.1-r291.36.1-r31
LowGHSA-6hcq-hmm3-jj3cspring-webmvc@6.1.12no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
5.10.4latesttoday5.5.022621542,972
5.10.321 days ago5.5.022611552,963
5.10.21 year ago5.5.022571522,835

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/wenerme/hazelcast.svg)](https://charts.stackradar.io/charts/wenerme/hazelcast)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Oct 2026 · scanned 6 Oct 2026 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.