GHSA-jj95-55cr-9597 · Severity: critical · Ecosystem: maven — Aerospike Java Client vulnerable to unsafe deserialization of server responses
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is running on. Versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 contain a patch for this issue.
Conclusion & alert: CVE-2023-36480 is rated High Risk (70.9/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.77%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-29 | 2.86% | 3.77% | +0.91% |
| 2 | 2025-11-21 | 4.83% | 2.86% | -1.97% |
| 3 | 2025-11-18 | — | 4.83% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-jj95-55cr-9597 · Severity: critical · Ecosystem: maven — Aerospike Java Client vulnerable to unsafe deserialization of server responses
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| aerospike | aerospike_java_client | < 4.5.0 | cpe:2.3:a:aerospike:aerospike_java_client:*:*:*:*:*:*:*:* |
| aerospike | aerospike_java_client | >= 5.0.0, < 5.2.0 | cpe:2.3:a:aerospike:aerospike_java_client:*:*:*:*:*:*:*:* |
| aerospike | aerospike_java_client | >= 6.0.0, < 6.2.0 | cpe:2.3:a:aerospike:aerospike_java_client:*:*:*:*:*:*:*:* |