PT-2026-35387 · Apache · Apache Mina

Venkatraman Kumar

·

Published

2026-04-27

·

Updated

2026-06-04

·

CVE-2026-41409

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache MINA versions 2.0.0 through 2.0.27 Apache MINA versions 2.1.0 through 2.1.10 Apache MINA versions 2.2.0 through 2.2.5
Description An issue exists in the getObject() function of the AbstractIoBuffer class due to an incomplete deserialization mechanism. The classname allowlist, which restricts which classes can be deserialized, is applied too late, potentially allowing a static initializer in a class to be executed before the check occurs. This flaw allows a remote attacker to execute arbitrary code on applications that call the getObject() function.
Recommendations Update to version 2.0.28 for versions 2.0.0 through 2.0.27. Update to version 2.1.11 for versions 2.1.0 through 2.1.10. Update to version 2.2.6 for versions 2.2.0 through 2.2.5. As a temporary workaround, restrict the use of the getObject() function.

Fix

RCE

LPE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06345
CLEANSTART-2026-DD05788
CLEANSTART-2026-LE11246
CLEANSTART-2026-LO22603
CLEANSTART-2026-RN56220
CVE-2026-41409
GHSA-F2WH-GRMH-R6JM
OESA-2026-2167
OESA-2026-2168
OESA-2026-2241
OESA-2026-2242
OESA-2026-2244

Affected Products

Apache Mina