
🚨Critical - Apache MINA Java Proxy Allow-list Bypass Regression (CVE-2026-94301) Apache MINA 2.0.x/2.1.x missed the resolveProxyClass() override that was only applied in 2.2.x for CVE-2026-47065. Attackers can bypass the deserialization allow-list by leveraging java.lang.reflect.Proxy during class resolution, enabling gadget invocation and potential RCE. MINA 2.2.x is not affected. 👉Affected: Apache MINA 2.0.0-2.0.30, 2.1.0-2.1.14



