CVE-2026-42778Disclosure(apache / mina)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache mina systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6. The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.1.0 <= 2.1.110, and 2.2.0 <= 2.2.6. The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mina

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-06-04); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
mina

Deep dive

Activity timeline12 mentions / 7d
01234Mentions · 2026-05-01: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 2Mentions · 2026-05-15: 1Mentions · 2026-06-01: 2Mentions · 2026-06-04: 4Mentions · 2026-07-21: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-04: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-04: 405-0105-1105-1305-1506-0106-0407-21
Signal classification3 categories
Disclosure
650.0%
Patch
325.0%
General
325.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-011
Patch1
2026-05-111
Disclosure1
2026-05-132
Disclosure1General1
2026-05-151
General1
2026-06-012
Disclosure2
2026-06-044
Disclosure2Patch2
2026-07-211
General1
Full discourse12 posts
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Apache MINA 2.1.12 and 2.2.7 patch two critical RCE flaws (CVE-2026-42778, CVE-2026-42779) that escaped previous security releases. Both vulnerabilities involve Java deserialization bypasses — one via static initializers, the other via type-checking gaps — allowing…

    Post summary

    Apache MINA has released patches (v2.1.12 and v2.2.7) to fix two critical RCE vulnerabilities involving Java deserialization bypasses, with details on the bypass mechanisms provided.

    2001039
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42778 (Incomplete fix for CVE-2026-41409): The ObjectSerializationDecoder's allowlist validation fails when a class's static initializer is invoked — the check is applied too late, allowing payloads to execute code even for non-allowlisted classes.

    Post summary

    The post discloses that CVE‑2026‑42778 remains vulnerable due to late allowlist validation in ObjectSerializationDecoder, enabling code execution via static initializers for non‑allowlisted classes.

    1001033
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    However: CVE-2026-42778: Static initializers of disallowed classes execute before the allowlist check, allowing gadgets like Runtime.exec() to fire even on rejected types. CVE-2026-42779: Primitive types (int, byte, etc.) and static class references (e.g., String.class)…

    Post summary

    The text announces two new CVEs, describing the mechanism that allows Runtime.exec gadget execution before allowlist checks, implying a remote code execution risk.

    1000033
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The Patch That Never Stuck: Apache MINA CVE-2026-42778 &amp; 42779 Expose Java Deserialization as the Infrastructure Weak Link. On May 5, 2026, Apache announced MINA 2.2.7 and 2.1.12 security releases addressing two critical-severity RCE vulnerabilities that should have been…

    Post summary

    The excerpt reports that Apache released patches for two critical RCE vulnerabilities in MINA related to Java deserialization, with no evidence of active exploitation or PoC.

    1000038
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42778: Untrusted Data Deserialization This vulnerability involves the deserialization of data from unknown network sources without proper validation. When a client sends specially-crafted serialized Java objects through the network, MINA reconstructs those objects…

    Post summary

    The text announces CVE-2026-42778, detailing deserialization of unvalidated Java objects through MINA, but provides no PoC, exploit, patches, or evidence of active exploitation.

    1000057
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Apache MINA 2.1.x and 2.2.x contain two critical remote code execution vulnerabilities (CVE-2026-42778 and CVE-2026-42779) stemming from insecure deserialization. The patches were written months ago but failed to merge into two release branches due to repository…

    Post summary

    Apache MINA 2.1.x/2.2.x suffer two critical RCE vulnerabilities due to insecure deserialization; patches exist but haven’t merged, leaving the issue unpatched.

    1000062
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42778 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet announces CVE-2026-42778 with a high CVSS score and critical severity but offers no further details about exploitation, patching, or mitigation.

    1000035
    210 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42778: Apache MINA Deserialization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04qbzL70

    Post summary

    The text merely references the CVE and its general name but provides no concrete details about PoC, exploitation, patching, or technical specifics.

    0000033
    32 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42778: Apache MINA Insecure Deserialization - What It Means for Your Business and How to Respond https://hubs.li/Q04gPGwv0

    Post summary

    The text refers to an article discussing CVE-2026-42778, highlighting insecure deserialization in Apache MINA, without evidence of PoC, exploit tools, active exploitation, or explicit patch details.

    0000043
    31 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42778-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The shared content includes only a URL and hashtags, providing no substantive information about CVE‑2026‑42778.

    0000026
    210 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache MINA の脆弱性 CVE-2026-42778/42779 が FIX:デシリアライズ欠陥と RCE の恐れ https://iototsecnews.jp/2026/05/04/new-apache-mina-vulnerabilities-open-door-to-remote-code-execution-attacks/ 今回の脆弱性である CVE-2026-42778 と CVE-2026-42779 の原因は、本来は適用されるはずだった修正が、内部的なマージ・エラーにより特定のブランチに反映されなかった点にあります。技術的な側面では、デシリアライズというデータ変換の過程で適切な検証が行われなかったり、本来は機能すべきセキュリティ・フィルタがプログラムの分岐によって回避されたりすることで、外部から送り込まれた悪意のコードが実行されてしまう状態にあります。特に AbstractIoBuffer.resolveClass() メソッドなどにおいて、チェック機能が働かずに Java オブジェクトがそのまま復元されてしまう仕組みは、攻撃の糸口となってしまいます。ご利用のチームは、ご注意ください。 #Apache #CVE202642778 #CVE202642779 #MINA

    Post summary

    The post announces that Apache MINA’s CVE-2026-42778/42779—a deserialization flaw that could enable remote code execution—has been fixed but the original patch was not properly merged, with no mention of active exploitation, PoC, or exploitation tools.

    00000122
    491 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 CVE-2026-42778: CWE-502 Deserialization of Untrusted Data CVE-CVE-2026-42779: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE Apache MINA 2.0.12 and 2.2.7 release https://lists.apache.org/thread/fhlx5k91hrkgyzh7yk1nghrn3k27gxy0

    Post summary

    Apache MINA’s 2.0.12 and 2.2.7 releases address CVE‑2026‑42778 and CVE‑2026‑42779, which are deserialization‑based RCE vulnerabilities—updating to these versions mitigates the risk.

    00000462
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachemina---

Explore more