The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache MINA | 2.0.0< 2.0.31 |
affected |
2.1.0< 2.1.15 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache MINA | 2.0.0 ~ 2.0.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47321 | 7.5 HIGH | Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate |
| CVE-2026-91863 | Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows den | |
| CVE-2026-91864 | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory | |
| CVE-2026-91865 | Apache Neethi: Crafted policy references cause exponential expansion during normalization | |
| CVE-2026-91866 | Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial | |
| CVE-2026-91867 | Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang t | |
| CVE-2026-82355 | Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, en | |
| CVE-2026-75158 | Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag autho | |
| CVE-2026-86473 | Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocabl |
No comments yet