CVE-2026-47065: Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TCPROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list .
ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes
Assessment: Fully addressed.
For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.") , attacker supplies com.myapp.SomeClass ) causes <clinit> of SomeClass — and many real-world classes have side-effecting static initialisers
Both issues have been fixed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47065?
CVE-2026-47065 has a critical severity rating of 9.8.
How do I fix CVE-2026-47065?
To fix CVE-2026-47065, update Apache MINA to the latest version where the issue has been fully addressed.
What type of vulnerability is CVE-2026-47065?
CVE-2026-47065 is a critical deserialization allow-list bypass vulnerability.
Which software is affected by CVE-2026-47065?
Apache MINA is the software affected by CVE-2026-47065.
When was CVE-2026-47065 published?
CVE-2026-47065 was published on June 3, 2026.