Deserialization of Untrusted Data in Apache MINA - CVE-2026-41409

 

Deserialization of Untrusted Data in Apache MINA - CVE-2026-41409

Published: April 28, 2026


Vulnerability identifier: #VU128406
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41409
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in AbstractIoBuffer.getObject() when deserializing untrusted objects. A remote attacker can supply a crafted serialized object to execute arbitrary code.

Only applications that call IoBuffer.getObject() are affected.


Affected software

Apache MINA
Storage Defender Copy Data Management
IBM Sterling B2B Integrator
Datastax Enterprise with IBM
IBM Sterling File Gateway
openEuler
apache-mina-javadoc
apache-mina-mina-statemachine
apache-mina-mina-http
apache-mina-mina-filter-compression
apache-mina-mina-core
apache-mina

How to mitigate CVE-2026-41409

Install security update from vendor's website.

Apache MINA - addressed in versions 2.0.28, 2.1.11, 2.2.6
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Sterling B2B Integrator - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
IBM Sterling File Gateway - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
apache-mina-javadoc - update to 2.1.11-1
apache-mina-mina-statemachine - update to 2.1.11-1
apache-mina-mina-http - update to 2.1.11-1
apache-mina-mina-filter-compression - update to 2.1.11-1
apache-mina-mina-core - update to 2.1.11-1
apache-mina - update to 2.1.11-1
Datastax Enterprise with IBM - update to 6.9.22

External References

Related Security Bulletins