logo

Apache MINA Patches Critical Framework Vulnerabilities

ID: 517b388d-485e-5ec1-a957-4cc0e70e07a9

STIX ID: report--517b388d-485e-5ec1-a957-4cc0e70e07a9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Do Son

...
...

### Executive summary This advisory describes two severe Apache MINA vulnerabilities—CVE-2026-47065 (critical deserialization bypass, CVSS 9.8) that can permit remote code execution by bypassing the allow-list during proxy class deserialization, and CVE-2026-47321 (decompression amplification) which can trigger memory exhaustion and DoS; maintainers released fixes (MINA 2.2.8, 2.1.13, 2.0.29) and recommend immediate upgrades and configuring CompressionFilter maxDecompressedSize.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.