top of page
perceptive_background_267k.jpg

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:











Apache MINA's AbstractIoBuffer.r…

Published:

30 April 2026 at 22:00:00

Alert date:

1 May 2026 at 18:06:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

CVE-2026-42779 is a vulnerability in Apache MINA where the fix for CVE-2026-41635 was not applied to certain branches. The issue exists in AbstractIoBuffer.resolveClass() which contains branches that don't check classes, bypassing the classname allowlist and allowing arbitrary code execution. Affected versions include Apache MINA 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6. The vulnerability affects applications using Apache MINA that call IoBuffer.getObject(). The issue is resolved in versions 2.1.12 and 2.2.7 by applying the classname allowlist earlier in the process.

Technical details

Mitigation steps:

Affected products:

Apache MINA

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page