Apache Product Security Update Advisory

Apache Product Security Update Advisory

Overview


A vulnerability has been discovered in Apache MINA among Apache products and a security update has been released.

Affected by


  • Apache MINA 2.2.7 and earlier.
  • Apache MINA 2.1.12 and earlier.

Resolved vulnerabilities


  • CVE-2026-42778: Untrusted Data deserialization vulnerability in Apache MINA, resulting in failure to securely restore external data.
  • CVE-2026-42779: A remote code execution vulnerability in Apache MINA, which could allow a threat actor to execute arbitrary code remotely.

What to do


vulnerability patches have been made available in the latest updates. you should update Apache MINA to the latest version of the Vulnerability Patch, 2.2.7 or 2.1.12, as instructed on the reference site.