Apache MINA 2.1.15 and 2.0.31 released
Emmanuel Lecharny <[email protected]> Sat, 27 Jun 2026 08:28:37 +0200
| Newsgroups | gmane.text.xml.xalan.devel,gmane.comp.apache.maven.announce,gmane.comp.apache.mina.user |
|---|---|
| Message-ID | <CAG8=FRiv73LuQE2-fQ84fpnExBLWZApptGPNBw_KPsUTr-=ENQ__24720.9997660079$1782541746$gmane$org@mail.gmail.com> |
The MINA project is pleased to announce the MINA 2.1.15 and 2.0.31 releases=
.
This is a bug fix release: A fix for CVE-2026-47065 ("Critical
Deserialization Allow-list Bypass via resolveProxyClass") hasn't been
backported to these two version.
Many thanks to **tonghuaroot** who have reported this mistake.
Affected versions:
------------------------
These issues affect **MINA** core versions prior to 2.1.15 and 2.0.31
Mitigation:
--------------
Those who used the versions 2.2.14, 2.0.30 and prior have to upgrade.
--=20
Regards,
Cordialement,
Emmanuel L=C3=A9charny
www.worteks.com