https://seclists.org/oss-sec/2026/q2/230: CVE-2026-41409: Apache MINA: CWE-502 Deserialization of Untrusted Data
Published Apr 27, 2026
·Updated
Affected Software
1 affected component
Apache MINA>=2.2.0<=2.2.5, >=2.1.0<=2.1.10, >=2.0.0<=2.0.27
Frequently Asked Questions
1
What is the severity of CVE-2026-41409?
CVE-2026-41409 is considered a serious vulnerability due to its potential for remote code execution via deserialization of untrusted data.
2
How do I fix CVE-2026-41409?
To mitigate CVE-2026-41409, update Apache MINA to the latest version above 2.2.5, 2.1.10, or 2.0.27.
3
Which versions of Apache MINA are affected by CVE-2026-41409?
Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5 are affected by CVE-2026-41409.
4
What type of vulnerability is CVE-2026-41409?
CVE-2026-41409 falls under CWE-502, which is the deserialization of untrusted data.
5
When was CVE-2026-41409 published?
CVE-2026-41409 was published on April 27, 2026.