CVE-2026-47065: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache MINA
CVE-2026-47065 is a critical deserialization vulnerability in Apache MINA affecting versions 2.0.0, 2.1.0, and 2.2.0. It involves bypassing accept-list filters during deserialization of java.lang.reflect.Proxy classes and triggering static initializers of allow-listed classes, potentially leading to remote code execution or other severe impacts. Both issues have been fully addressed by the vendor. No explicit patch or official fix details are provided in the input data.
AI Analysis
Technical Summary
This vulnerability concerns Apache MINA's deserialization process where the resolveProxyClass method was not overridden, allowing attackers to bypass accept-list filters by supplying serialized streams containing TC_PROXYCLASSDESC markers for java.lang.reflect.Proxy. The default ObjectInputStream.resolveProxyClass implementation uses Class.forName on each interface name, constructing proxy classes without enforcing the accept-list. Additionally, deserializing allow-listed classes triggers their static initializers before instance construction, which can execute side-effecting code. Both issues have been fully addressed by Apache, though no explicit patch version or advisory is provided.
Potential Impact
Successful exploitation could allow an unauthenticated remote attacker to bypass deserialization accept-list filters and trigger static initializers of classes, potentially leading to arbitrary code execution, complete confidentiality, integrity, and availability compromise of affected systems. The CVSS 3.1 score is 9.8 (critical), reflecting network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
The vendor has fully addressed these issues. However, no explicit patch or official fix version is provided in the available data. Users should consult the Apache Software Foundation advisories or official Apache MINA project communications for the latest patch or update information and apply any available updates promptly. Until then, consider restricting deserialization of untrusted data and monitoring for suspicious activity related to deserialization.
CVE-2026-47065: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache MINA
Description
CVE-2026-47065 is a critical deserialization vulnerability in Apache MINA affecting versions 2.0.0, 2.1.0, and 2.2.0. It involves bypassing accept-list filters during deserialization of java.lang.reflect.Proxy classes and triggering static initializers of allow-listed classes, potentially leading to remote code execution or other severe impacts. Both issues have been fully addressed by the vendor. No explicit patch or official fix details are provided in the input data.
CVSS v3.1
Score 9.8critical
Affected software
pkg:maven/org.apache.mina/mina-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability concerns Apache MINA's deserialization process where the resolveProxyClass method was not overridden, allowing attackers to bypass accept-list filters by supplying serialized streams containing TC_PROXYCLASSDESC markers for java.lang.reflect.Proxy. The default ObjectInputStream.resolveProxyClass implementation uses Class.forName on each interface name, constructing proxy classes without enforcing the accept-list. Additionally, deserializing allow-listed classes triggers their static initializers before instance construction, which can execute side-effecting code. Both issues have been fully addressed by Apache, though no explicit patch version or advisory is provided.
Potential Impact
Successful exploitation could allow an unauthenticated remote attacker to bypass deserialization accept-list filters and trigger static initializers of classes, potentially leading to arbitrary code execution, complete confidentiality, integrity, and availability compromise of affected systems. The CVSS 3.1 score is 9.8 (critical), reflecting network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
The vendor has fully addressed these issues. However, no explicit patch or official fix version is provided in the available data. Users should consult the Apache Software Foundation advisories or official Apache MINA project communications for the latest patch or update information and apply any available updates promptly. Until then, consider restricting deserialization of untrusted data and monitoring for suspicious activity related to deserialization.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-05-18T16:53:39.555Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a200686e29bf47b50a6e4a8
Added to database: 06/03/2026, 10:48:38 UTC
Last enriched: 07/14/2026, 10:00:39 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 426
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.