CVE-2026-41409
published 2026-05-01CVE-2026-41409: The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.2th percentile
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.
The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.1.0 <= 2.1.110, and 2.2.0 <= 2.2.6.
The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mina | >= 2.0.0 < 2.0.28 | 2.0.28 |
| apache | mina | >= 2.1.0 < 2.1.12 | 2.1.12 |
| apache | mina | >= 2.1.0 < 2.1.11 | 2.1.11 |
| apache | mina | >= 2.2.0 < 2.2.7 | 2.2.7 |
| apache | mina | >= 2.2.0 < 2.2.6 | 2.2.6 |
| jenkins | jenkins | — | — |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
vendor_redhat·2026-05-01·CVSS 9.8
CVE-2026-42778 [CRITICAL] CWE-502 Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
A flaw was found in Apache MINA. An incomplete fix for a deserialization issue in the `AbstractIoBuffer.getObject()` method allowed a static initializer in a class to be executed before the classname allowlist was applied. This vulnerability allows a remote attacker to execute arbitrary code in applications calling the `IoBuffer.getObject()` method.
Statement: Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.
Package: jenkins (OpenShift Developer Tools and Services) - Affected
Package: jenkins-2-plugins (OpenShift Developer Tools and Services) - Affected
P
Red Hat
Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
vendor_redhat·2026-04-27·CVSS 10.0
CVE-2026-41409 [CRITICAL] CWE-502 Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
A flaw was found in Apache MINA. An incomplete fix for a deserialization vulnerability in the `AbstractIoBuffer.getObject()` method allowed a static initializer in a class to be executed before the classname allowlist was applied. This could enable a remote attacker to execute arbitrary code by sending specially crafted data to an application using Apache MINA that calls `IoBuffer.getObject()`.
Statement: This is a Critical deserialization flaw in Apache MINA, allowing remote attackers to execute arbitrary code. It addresses an incomplete fix for CVE-2024-52046 which could bypass security controls. Red Hat products are affected if they utilize Apache MINA and invoke the `IoBuffer.getObject()` method.
P
GHSA
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
ghsa·2026-05-01·CVSS 10.0
CVE-2026-42778 [CRITICAL] CWE-502 Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.
The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade.
GHSA
GHSA-995c-6rp3-4m4x: The fix for CVE-2026-41409 was not applied to the 2
ghsa_unreviewed·2026-05-01·CVSS 10.0
CVE-2026-42778 [CRITICAL] CWE-502 GHSA-995c-6rp3-4m4x: The fix for CVE-2026-41409 was not applied to the 2
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.
The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of c
GHSA
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
ghsa·2026-04-27·CVSS 10.0
CVE-2026-41409 [CRITICAL] CWE-502 Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5.
The problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
VulDB
Apache MINA up to 2.0.27/2.1.10/2.2.5 AbstractIoBuffer.getObject deserialization
vuldb·2026-04-27·CVSS 9.8
CVE-2026-41409 [CRITICAL] Apache MINA up to 2.0.27/2.1.10/2.2.5 AbstractIoBuffer.getObject deserialization
A vulnerability described as critical has been identified in Apache MINA up to 2.0.27/2.1.10/2.2.5. The impacted element is the function AbstractIoBuffer.getObject. The manipulation results in deserialization.
This vulnerability is cataloged as CVE-2026-41409. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42778 apache-commons-vfs: deserialization of untrusted data (incomplete fix for CVE-2026-41409) [fedora-all]
bugzilla·2026-05-14·CVSS 9.8
CVE-2026-42778 [CRITICAL] CVE-2026-42778 apache-commons-vfs: deserialization of untrusted data (incomplete fix for CVE-2026-41409) [fedora-all]
CVE-2026-42778 apache-commons-vfs: deserialization of untrusted data (incomplete fix for CVE-2026-41409) [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41409 apache-sshd: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
bugzilla·2026-05-14·CVSS 9.8
CVE-2026-41409 [CRITICAL] CVE-2026-41409 apache-sshd: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
CVE-2026-41409 apache-sshd: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41409 apache-commons-vfs: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
bugzilla·2026-05-14·CVSS 9.8
CVE-2026-41409 [CRITICAL] CVE-2026-41409 apache-commons-vfs: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
CVE-2026-41409 apache-commons-vfs: Apache MINA: Arbitrary code execution via incomplete deserialization fix [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42778 Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
bugzilla·2026-05-01·CVSS 10.0
CVE-2026-42778 [CRITICAL] CVE-2026-42778 Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
CVE-2026-42778 Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6.
The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by
applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
The fix for CVE-
Bugzilla
CVE-2026-41409 Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
bugzilla·2026-04-27·CVSS 10.0
CVE-2026-41409 [CRITICAL] CVE-2026-41409 Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
CVE-2026-41409 Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.
Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5.
The problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by
applying the classname allowlist earlier.
Affected are applications using Apache MINA that call IoBuffer.getObject().
Applications using Apache MINA are advised to upgrade
2026-05-01
Published