Mina CVE Vulnerabilities
By Apache — 2 known vulnerabilities
Critical
2
High
0
Medium
0
Low
0
None
0
All Mina CVEs
CVE-2026-42779
9.8
critical
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the clas
May 1, 2026
CVE-2026-42778
9.8
critical
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a s
May 1, 2026