


Perceptive Security
SOC/SIEM Consultancy

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stre…
Published:
2 juni 2026 om 22:00:00
Alert date:
3 juni 2026 om 12:01:10
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
Two critical vulnerabilities in Java ObjectInputStream deserialization that allow filter bypass. ZDRES-232 enables bypassing accepted classes list via java.lang.reflect.Proxy when TC_PROXYCLASSDESC marker is present. ZDRES-233 allows triggering static initializers of allow-listed classes during deserialization before instance construction. Both issues enable attackers to execute code through side-effecting static initializers in real-world classes. The vulnerabilities affect JDK's ObjectInputStream implementation and have been fully addressed.
Technical details
Mitigation steps:
Affected products:
Java JDK
ObjectInputStream
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47065
https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
