CVE-2026-47065
Description
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list .
ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes
Assessment: Fully addressed.
For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*") , attacker supplies com.myapp.SomeClass ) causes of SomeClass — and many real-world classes have side-effecting static initialisers
Both issues have been fixed.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.mina:mina-coreMaven | >= 2.2.0, < 2.2.8 | 2.2.8 |
org.apache.mina:mina-coreMaven | >= 2.1.0, < 2.1.13 | 2.1.13 |
org.apache.mina:mina-coreMaven | < 2.0.29 | 2.0.29 |
Affected products
14- osv-coords11 versionspkg:apk/chainguard/apache-nifipkg:apk/chainguard/guacamole-client-extensionspkg:apk/chainguard/hadoop-fips-3.5pkg:apk/chainguard/jenkins-2-openjdk-21pkg:apk/chainguard/jenkins-2-openjdk-25pkg:apk/chainguard/jenkins-2.568pkg:apk/chainguard/jenkins-2.568-openjdk-21pkg:apk/chainguard/jenkins-2.568-openjdk-25pkg:apk/wolfi/apache-nifipkg:apk/wolfi/jenkins-2-openjdk-21pkg:apk/wolfi/jenkins-2-openjdk-25
< 2.10.0-r4+ 10 more
- (no CPE)range: < 2.10.0-r4
- (no CPE)range: < 1.6.0-r13
- (no CPE)range: < 3.5.0-r2
- (no CPE)range: < 2.577-r0
- (no CPE)range: < 2.577-r0
- (no CPE)range: < 2.568.1-r2
- (no CPE)range: < 2.568.1-r2
- (no CPE)range: < 2.568.1-r2
- (no CPE)range: < 2.10.0-r4
- (no CPE)range: < 2.577-r0
- (no CPE)range: < 2.577-r0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-v3pr-hxpr-mfm8ghsaADVISORY
- lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyjnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-47065ghsaADVISORY
News mentions
0No linked articles in our index yet.