Allow-List Bypass Vulnerability in Apache MINA Product by Apache
CVE-2026-94301
9.8CRITICAL
What is CVE-2026-94301?
A significant vulnerability exists in Apache MINA where versions 2.0.29 and 2.1.13, and subsequent releases, do not implement the necessary override for resolveProxyClass(), leading to a potential allow-list bypass. This oversight occurs despite fixes being committed to the 2.2.X branch, leaving earlier maintenance branches susceptible to exploitation. The failure to address this issue effectively in the older branches exposes users to risks associated with unauthorized access and manipulation.
Affected Version(s)
Apache MINA 2.0.0 < 2.0.31
Apache MINA 2.1.0 < 2.1.15