Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.mina/mina-core
  4. ›
  5. CVE-2026-47065

CVE-2026-47065: Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass

June 3, 2026 (updated July 13, 2026)

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy

Assessment: Fully addressed.

When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list .

ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes

Assessment: Fully addressed.

For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*") , attacker supplies com.myapp.SomeClass ) causes of SomeClass — and many real-world classes have side-effecting static initialisers

Both issues have been fixed.

References

  • github.com/advisories/GHSA-v3pr-hxpr-mfm8
  • lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
  • nvd.nist.gov/vuln/detail/CVE-2026-47065

Code Behaviors & Features

Detect and mitigate CVE-2026-47065 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.0.29, all versions starting from 2.1.0 before 2.1.13, all versions starting from 2.2.0 before 2.2.8

Fixed versions

  • 2.0.29
  • 2.1.13
  • 2.2.8

Solution

Upgrade to versions 2.0.29, 2.1.13, 2.2.8 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

maven/org.apache.mina/mina-core/CVE-2026-47065.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:38 +0000.