CVE-2026-41635Disclosure(apache / mina)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache mina systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling Class.forName().  Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5. The problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call  IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mina

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-27); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
mina

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-04-27: 5Mentions · 2026-04-28: 2Mentions · 2026-05-01: 1Mentions · 2026-06-13: 1Patch / Workaround · 2026-04-27: 3Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-27: 5Technical Details · 2026-04-28: 2Technical Details · 2026-05-01: 104-2704-2805-0106-13
Signal classification2 categories
Disclosure
555.6%
Patch
444.4%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-275
Disclosure3Patch2
2026-04-282
Disclosure1Patch1
2026-05-011
Patch1
2026-06-131
Disclosure1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache MINA (CVE-2026-41635) suffers a critical 9.8 CVSS RCE flaw. Learn how a deserialization filter bypass puts servers at risk and how to patch today. #ApacheMINA #CyberSecurity #RCE #InfoSec #JavaSecurity #PatchNow #CVE https://securityonline.info/apache-mina-deserialization-rce-cve-2026-41635-patch-guide/ https://t.co/SBuDpYdeTm

    Post summary

    The post highlights a critical RCE flaw in Apache MINA (CVE-2026-41635), provides technical details about a deserialization filter bypass, and directs readers to a patch guide for remediation.

    00042426
    12.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41409: Apache MINA: CWE-502 Deserialization of Untrusted Data https://www.openwall.com/lists/oss-security/2026/04/27/3 ZDRES-059: CVE-2026-41635: Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE https://www.openwall.com/lists/oss-security/2026/04/27/4

    Post summary

    The message announces two new Apache MINA vulnerabilities—one involving deserialization of untrusted data (CWE‑502) and another enabling full object deserialization RCE—without providing PoC, exploit code, or patch information.

    01040341
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Apache MINA deserialization bypass → RCE (CVE-2026-41635) A flaw in AbstractIoBuffer.resolveClass() skips classname allowlist checks for certain static/primitive types, allowing unsafe deserialization via IoBuffer.getObject(). This can lead to remote code execution in affected applications. 👉 Affected: 2.0.0-2.0.27 | 2.1.0-2.1.10 | 2.2.0-2.2.5 | Upgrade: 2.0.28 / 2.1.11 / 2.2.6

    Post summary

    The post alerts users to a critical deserialization flaw in Apache MINA that can lead to RCE and recommends upgrading to patched versions.

    0004094
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 1, 2026, security researchers disclosed CVE-2026-42779 in Apache MINA, a critical Java networking framework used across enterprise messaging systems, IoT platforms, and distributed applications. The vulnerability is a re-emergence of an older flaw (CVE-2026-41635)…

    Post summary

    Researchers disclosed CVE-2026-42779, a critical vulnerability in Apache MINA that re‑emerges from an earlier flaw, without providing PoC, exploitation, or patch details.

    1000023
    267 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical arbitrary code execution vulnerability in #Apache #MINA. CVE-2026-41635 CVSS: 9.8. This can allow attackers to bypass the classname allowlist. https://ccb.belgium.be/advisories/warning-critical-arbitrary-code-execution-vulnerability-apache-mina-patch-immediately #Patch #Patch #Patch

    Post summary

    The advisory warns of a critical arbitrary code execution flaw in Apache MINA (CVE‑2026‑41635) with a CVSS score of 9.8 and urges users to apply the patch immediately.

    01000282
    7.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Patch

    🚨 CRITICAL — CVE-2026-42779 The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42779 #Apache #CyberSecurity #InfoSec

    Post summary

    The tweet alerts to a critical CVE‑2026‑42779 with a CVSS score of 9.8, notes that no patch has been released, and links to a detailed analysis.

    0000056
    460 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing th… https://www.cve.org/CVERecord?id=CVE-2026-41635

    Post summary

    The CVE involves a class‑check bypass in Apache MINA's AbstractIoBuffer.resolveClass, potentially enabling arbitrary class loading; no PoC, exploit, or mitigation is disclosed.

    00000108
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41635 Remote Code Execution via Classname Allowlist Bypass in Apache MINA https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41635

    Post summary

    The text announces CVE-2026-41635, a remote code execution flaw in Apache MINA caused by a classname allowlist bypass, but offers no further details beyond the basic description.

    0000053
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-41635 #Apache #CyberSecurity #InfoSec

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-41635) in Apache MINA, providing brief technical details and a CVSS score, but does not indicate an available PoC, exploit, or active exploitation.

    0000047
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachemina---

Explore more