Apache disclosed CVE-2026-94301, confirming that MINA versions 2.0.0 through 2.0.30 and 2.1.0 through 2.1.14 remain vulnerable to the deserialization allow-list bypass previously tracked as CVE-2026-47065 / ZDRES-232. The required resolveProxyClass() override was applied only to the 2.2.x branch, allowing java.lang.reflect.Proxy objects to bypass acceptMatchers filtering in affected maintenance branches.
Earlier announcements had described MINA 2.0.29 and 2.1.13 as fully remediated, but the necessary change was not included in those branches. Organizations using affected MINA versions should upgrade to 2.0.31 or 2.1.15, which contain the missing fix, and review applications that deserialize untrusted data.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Apache MINA disclosed that the resolveProxyClass() fix for CVE-2026-47065 had been committed only to the 2.2.x branch, leaving versions 2.0.0 through 2.0.30 and 2.1.0 through 2.1.14 vulnerable. The issue was assigned CVE-2026-94301; MINA identified 2.0.31 and 2.1.15 as the fixed releases.
Apache MINA announced bug-fix releases 2.1.15 and 2.0.31. The release announcement said the CVE-2026-47065 fix had not been backported to these releases and advised users of older versions to upgrade.
Apache MINA released CVE-2026-47065/ZDRES-232 to address a resolveProxyClass-related acceptMatchers allow-list bypass involving java.lang.reflect.Proxy objects. MINA stated that versions 2.2.8, 2.1.13, and 2.0.29 fully addressed the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcelists.apache.org
Open sourcelists.apache.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.