CVE-2024-52046 is an unsafe Java deserialization vulnerability in Apache MINA core's ObjectSerializationDecoder. The decoder processes incoming serialized objects using Java native deserialization without sufficient security checks, allowing specially crafted serialized data to potentially trigger remote code execution. Affected releases are 2.0.x before 2.0.27, 2.1.x before 2.1.10, and 2.2.x before 2.2.4. Applications are affected only when they invoke IoBuffer#getObject(), including through a ProtocolCodecFilter configured with ObjectSerializationCodecFactory. Apache MINA's FtpServer, SSHd, and Vysper subprojects are not affected. Subsequent vulnerabilities identified bypasses and incomplete enforcement in the original class-allowlist remediation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small single-script Python exploit repository for CVE-2024-52046 targeting Apache MINA's ObjectSerializationDecoder unsafe deserialization flaw. The repository contains one main code file (CVE-2024-52046.py), a README with vulnerability background and usage examples, a minimal requirements file, and license metadata. The exploit is not tied to a larger framework. The Python script is an operational PoC that connects to an operator-specified host and TCP port and sends crafted Java serialized object data. Its main capability is unauthenticated remote command execution against vulnerable Apache MINA services when a compatible Java gadget chain is present on the target. It supports multiple ysoserial gadget names, command execution mode, a vulnerability-check mode, gadget listing, verbose logging, and an interactive shell mode. Payload generation is delegated to a local ysoserial.jar via subprocess invocation of `java -jar ysoserial.jar <gadget> <command>`. If ysoserial is unavailable, the script falls back to generating a minimal serialized Java object intended more for detection/probing than code execution. Fingerprintable observables are limited: the exploit targets arbitrary operator-provided TCP endpoints rather than hardcoded victim infrastructure. It searches several local filesystem paths for ysoserial.jar and references example targets and example command artifacts in the README. Overall, this is a real exploit PoC with practical offensive capability, but it depends on external Java tooling and target-side gadget availability, so it is best classified as OPERATIONAL rather than fully weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier Apache MINA vulnerability involving object deserialization through AbstractIoBuffer.getObject(). Its incomplete fix allowed class static initialization to occur before class allowlist validation, forming the background to the subsequent vulnerabilities.
A prior Apache MINA vulnerability referenced as the original issue whose fix was incomplete, leading to CVE-2026-41409.
An earlier critical Apache MINA deserialization vulnerability in the ObjectSerializationDecoder component whose initial fix was bypassed by CVE-2026-41409.
A prior Apache MINA remote code execution vulnerability involving ObjectSerializationDecoder and insufficient security checks during Java native deserialization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.