PT-2026-36315 · Apache · Apache Mina

Published

2026-05-01

·

Updated

2026-05-05

·

CVE-2026-42779

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache MINA versions 2.1.0 through 2.1.11 Apache MINA versions 2.2.0 through 2.2.6
Description Apache MINA contains a flaw in the resolveClass() function of AbstractIoBuffer where one of the execution branches, specifically for primitive types or static classes, fails to validate the class against the classname allowlist. This bypass occurs during object deserialization when IoBuffer.getObject() is called, potentially allowing remote code execution on the server without authentication.
Recommendations Upgrade to version 2.1.12 for the 2.1.X branch. Upgrade to version 2.2.7 for the 2.2.X branch.

Fix

RCE

LPE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-42779

Affected Products

Apache Mina