Apache Mina Vulnerabilities

4 advisories affecting Apache Mina

4

Total CVEs

4

Critical

0

High

CVE-2026-42778

May 1, 2026

Critical (9.8)

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inco...

Read Advisory

CVE-2026-42779

May 1, 2026

Critical (9.8)

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one...

Read Advisory

CVE-2026-41409

Apr 27, 2026

Critical (9.8)

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in ...

Read Advisory

CVE-2026-41635

Apr 27, 2026

Critical (9.8)

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.