TopVuln

High-risk vulnerability digests

CVE-2026-41409

  • CRITICAL

OESA-2026-2168 apache-mina security update

Details

CVSS v3
9.8
NVD published
2026-04-27 10:16:09
EPSS
0.2% probability · 39.7th percentile — 2026-05-12
Affected versions
Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, 2.2.0 <= 2.2.5
Summary
The prior fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer was incomplete. The classname allowlist check is applied after static class initializers can execute, leaving the system vulnerable to deserialization attacks. Attackers can exploit this flaw to execute arbitrary code on vulnerable servers.
Remediation
Upgrade Apache MINA to the latest patched releases 2.0.28, 2.1.11, or 2.2.6 to apply the allowlist check before any untrusted code execution. Audit all deployed applications using Apache MINA to ensure they are running supported, patched versions.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.