{
  "threat_severity" : "Low",
  "public_date" : "2026-04-27T09:20:12Z",
  "bugzilla" : {
    "description" : "Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix",
    "id" : "2463175",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2463175"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-502",
  "details" : [ "The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.\nAffected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5.\nThe problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by \napplying the classname allowlist earlier.\nAffected are applications using Apache MINA that call IoBuffer.getObject().\nApplications using Apache MINA are advised to upgrade", "A flaw was found in Apache MINA. An incomplete fix for a deserialization vulnerability in the `AbstractIoBuffer.getObject()` method allowed a static initializer in a class to be executed before the classname allowlist was applied. This could enable a remote attacker to execute arbitrary code by sending specially crafted data to an application using Apache MINA that calls `IoBuffer.getObject()`." ],
  "statement" : "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
  "affected_release" : [ {
    "product_name" : "OpenShift Developer Tools and Services 4.12",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60247",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.12::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628667"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.13",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60249",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.13::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628681"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60248",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.14::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533561"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60239",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.15::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533565"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.16",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60251",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.16::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125166"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.17",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60246",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.17::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124635"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.18",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60250",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.18::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125069"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.19",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60252",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.19::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124632"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.20",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60259",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.20::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124925"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.21",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60254",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.21::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125311"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.22",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60256",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.22::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124779"
  } ],
  "package_state" : [ {
    "product_name" : "OpenShift Developer Tools and Services",
    "fix_state" : "Affected",
    "package_name" : "jenkins",
    "cpe" : "cpe:/a:redhat:ocp_tools"
  }, {
    "product_name" : "OpenShift Developer Tools and Services",
    "fix_state" : "Affected",
    "package_name" : "jenkins-2-plugins",
    "cpe" : "cpe:/a:redhat:ocp_tools"
  }, {
    "product_name" : "Red Hat AMQ Broker 7",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:amq_broker:7"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Fix deferred",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "javapackages-tools:201801/maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "maven:3.9/maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Fix deferred",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  }, {
    "product_name" : "streams for Apache Kafka 2",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:amq_streams:2"
  }, {
    "product_name" : "streams for Apache Kafka 3",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:amq_streams:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-41409\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41409\nhttps://lists.apache.org/thread/9ddvsq6c4l5bhwq8l14sob4f8qjvx5c9" ],
  "name" : "CVE-2026-41409",
  "csaw" : false
}