Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-94301: Apache MINA 2.0/2.1 allows filter bypass
CVE-2026-94301 · published today
Summary
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an attacker could potentially get past the intended allow‑list filtering. Upgrade to MINA 2.2.8 or later, or apply the missing code change, to close the gap.
What to do
- Update apache software foundation apache mina to version 2.0.31 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache mina | < 2.0.31 |
Original advisory text
Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the
2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published21 Sep 2026
Updated21 Sep 2026
First seen21 Sep 2026
Track software like this
Free during beta