CVE 9.8 CRITICAL

Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2)_CVE-2026-42778

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:




The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.




Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.




The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.




Affected are applications using Apache MINA that call IoBuffer.getObject().




Applications using Apache MINA are advised to upgrade






The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.




Affected versions are Apache MINA 2.1.0 <= 2.1.110, and 2.2.0 <= 2.2.6.




The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.




Affected are applications using Apache MINA that call IoBuffer.getObject().




Applications using Apache MINA are advised to upgrade

AI Analysis

Incomplete fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() allows deserialization of untrusted data

Basic Information

ID CVE-2026-42778
Source apache
Published May 1, 2026 at 10:01

Affected Product

Vendor Apache Software Foundation
Product Apache MINA
Version 2.2.X
Affected Versions Apache Software Foundation Apache MINA 2.2.X
Apache Software Foundation Apache MINA 2.1.X

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Apache Software Foundation
Product Apache MINA
Version 2.1.0-2.1.11, 2.2.0-2.2.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.