Apache MINA 2.1.15 and 2.0.31 released

Emmanuel Lecharny <[email protected]> Sat, 27 Jun 2026 08:28:37 +0200
Newsgroups gmane.text.xml.xalan.devel,gmane.comp.apache.maven.announce,gmane.comp.apache.mina.user
Message-ID <CAG8=FRiv73LuQE2-fQ84fpnExBLWZApptGPNBw_KPsUTr-=ENQ__24720.9997660079$1782541746$gmane$org@mail.gmail.com>
The MINA project is pleased to announce the MINA 2.1.15 and 2.0.31 releases=
.

This is a bug fix release: A fix for CVE-2026-47065 ("Critical
Deserialization Allow-list Bypass via resolveProxyClass") hasn't been
backported to these two version.

Many thanks to **tonghuaroot** who have reported this mistake.

Affected versions:
------------------------

These issues affect **MINA** core versions prior to 2.1.15 and 2.0.31

Mitigation:
--------------

Those who used the versions 2.2.14, 2.0.30 and prior have to upgrade.

--=20
Regards,
Cordialement,
Emmanuel L=C3=A9charny
www.worteks.com