#apachemina
CVE-2026-94301 - apache mina
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachemina #apachefoundation #CVE #infosec
CVE-2026-94301: Apache MINA 2.0/2.1 allows filter bypass
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects.
stackflag.com
September 21, 2026 at 3:00 PM
#apachemina using sshd Stumbled upon this. Using net.i2p.crypto:eddsa:0.3.0 running three hosts; executing a couple of commands via sshclient: takes ca. 1.75 seconds using another provider org.bouncycastle:bcpkix-jdk18on the same executiong takes ca. 2.4 seconds ? What the heck?
November 18, 2025 at 11:54 AM
Apache MINA users: CRITICAL deserialization bug exposes 2.1.0 – 2.1.11 & 2.2.0 – 2.2.6 to remote code execution. Upgrade to 2.1.12/2.2.7 ASAP! 🚨 https://radar.offseq.com/threat/cve-2026-42779-cwe-502-deserialization-of-untruste-d7661188 #OffSeq #ApacheMINA #Security
CVE-2026-42779: CWE-502 Deserialization of Untrusted Data in Apache Software Fou
Apache MINA's AbstractIoBuffer.resolveClass() method contains two branches for resolving classes during deserialization. One branch, handling static classes or primitive types, does not enforce the classname allowlist, which is designed to
radar.offseq.com
May 2, 2026 at 12:00 AM
Apache MINA 2.1.X & 2.2.X face a CRITICAL deserialization flaw (CVE-2026-42778). Patch to 2.1.12 or 2.2.7 to prevent exploit. Focus on IoBuffer.getObject() use. Details: https://radar.offseq.com/threat/cve-2026-42778-cwe-502-deserialization-of-untruste-db0b103e #OffSeq #ApacheMINA #Security
CVE-2026-42778: CWE-502 Deserialization of Untrusted Data in Apache Software Fou
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes a
radar.offseq.com
May 1, 2026 at 10:30 AM
Critical RCE vulnerabilities found in Apache MINA. Upgrade to versions 2.2.7 or 2.1.12 immediately to secure your systems. #CyberSecurity #ApacheMINA #RCE #SecurityUpdate Link: thedailytechfeed.com/critical-rem...
May 5, 2026 at 5:21 PM