PT-2026-35373 · Apache · Apache Mina

·

CVE-2026-41635

·

Published

2026-04-27

·

Updated

2026-06-13

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache MINA versions 2.0.0 through 2.0.27 Apache MINA versions 2.1.0 through 2.1.10 Apache MINA versions 2.2.0 through 2.2.5
Description A flaw in the resolveClass() function of AbstractIoBuffer allows a bypass of the classname allowlist for static classes or primitive types. This occurs because one of the execution branches fails to validate the class, enabling unsafe deserialization when applications call IoBuffer.getObject(). This can lead to remote code execution.
Recommendations Upgrade to version 2.0.28 for versions 2.0.0 through 2.0.27. Upgrade to version 2.1.11 for versions 2.1.0 through 2.1.10. Upgrade to version 2.2.6 for versions 2.2.0 through 2.2.5.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10859
CLEANSTART-2026-DD05788
CLEANSTART-2026-LE11246
CLEANSTART-2026-LO22603
CLEANSTART-2026-RN56220
CVE-2026-41635
GHSA-8297-V2RF-2P32
OESA-2026-2167
OESA-2026-2168
OESA-2026-2241
OESA-2026-2242
OESA-2026-2244

Affected Products

Apache Mina