Bug#1139162: mina2: CVE-2026-47065 CVE-2026-47321

Salvatore Bonaccorso carnil at debian.org
Sat Jun 6 19:44:10 BST 2026


Source: mina2
Version: 2.2.1-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerabilities were published for mina2.

CVE-2026-47065[0]:
| ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter
| Bypass via java.lang.reflect.Proxy   Assessment: Fully addressed.
| When the serialised stream contains a TC_PROXYCLASSDESC (the marker
| for a java.lang.reflect.Proxy ), JDK’s
| ObjectInputStream.readProxyDesc()  is dispatched. JDK then calls the
| default  ObjectInputStream.resolveProxyClass(interfaces)
| implementation, which  performs Class.forName(intf, false,
| latestUserDefinedLoader()) for EACH  interface name and constructs
| the proxy class — bypassing the accepted  classes list .
| ZDRES-233: Class.forName(name, initialize=true, classLoader) in
| readClassDescriptor Triggers Static Initialiser of Allow-Listed
| Classes   Assessment: Fully addressed.   For ANY class on the allow-
| list, deserialising a stream that names it triggers the class’s
| (static initialiser) BEFORE any instance is constructed. This means
| an  attacker who supplies a class name on the allow-list (e.g., the
| developer wrote accept(“com.myapp.*") , attacker supplies
| com.myapp.SomeClass ) causes <clinit> of SomeClass — and many
| real-world classes have side-effecting static initialisers   Both
| issues have been fixed.


CVE-2026-47321[1]:
| Unbounded Decompression Amplification DoS in Apache Mina Zlib.inflate


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-47065
    https://www.cve.org/CVERecord?id=CVE-2026-47065
[1] https://security-tracker.debian.org/tracker/CVE-2026-47321
    https://www.cve.org/CVERecord?id=CVE-2026-47321
[2] https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore


More information about the pkg-java-maintainers mailing list