CVE-2026-47065
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list .
ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes
Leer descripción completaMostrar menos
Assessment: Fully addressed.
For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*") , attacker supplies com.myapp.SomeClass ) causes <clinit> of SomeClass — and many real-world classes have side-effecting static initialisers
Both issues have been fixed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 % - Impacto principal
T1059Command and Scripting Interpreterexecution55 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-502
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-47065",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-47065",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-03T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@apache.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache MINA",
"versions": [
{
"status": "affected",
"version": "2.2.0",
"lessThan": "2.2.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.1.0",
"lessThan": "2.1.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.29",
"versionType": "semver"
}
],
"packageName": "org.apache.mina:mina-core",
"collectionURL": "https://repo.maven.apache.org/maven2/org/apache/mina",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-03T11:16:19.800",
"references": [
{
"url": "https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "security@apache.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\n\n\nAssessment: Fully addressed.\n\n\nWhen the serialised stream contains a TC_PROXYCLASSDESC (the marker \nfor a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc()\n is\ndispatched. JDK then calls the default \nObjectInputStream.resolveProxyClass(interfaces) implementation, which \nperforms Class.forName(intf, false, latestUserDefinedLoader()) for EACH \ninterface name and constructs the proxy class — bypassing the accepted\n classes list .\n\n\nZDRES-233: Class.forName(name, initialize=true, classLoader) in \nreadClassDescriptor Triggers Static Initialiser of Allow-Listed Classes\n\n\nAssessment: Fully addressed.\n\n\nFor ANY class on the allow-list, deserialising a stream that names it triggers the class’s \n (static initialiser) BEFORE any instance is constructed. This means an \nattacker who supplies a class name on the allow-list (e.g., the \ndeveloper wrote accept(“com.myapp.*\") , attacker supplies \ncom.myapp.SomeClass ) causes <clinit> of SomeClass — and many \nreal-world classes have side-effecting static initialisers\n\n\nBoth issues have been fixed."
},
{
"lang": "es",
"value": "ZDRES-232: resolveProxyClass no anulado - Omisión del filtro acceptMatchers mediante java.lang.reflect.Proxy\n\nEvaluación: Completamente abordado.\n\nCuando el flujo serializado contiene un TC_PROXYCLASSDESC (el marcador para un java.lang.reflect.Proxy), se despacha ObjectInputStream.readProxyDesc() del JDK. El JDK luego llama a la implementación predeterminada de ObjectInputStream.resolveProxyClass(interfaces), que realiza Class.forName(intf, false, latestUserDefinedLoader()) para CADA nombre de interfaz y construye la clase proxy, omitiendo la lista de clases aceptadas.\n\nZDRES-233: Class.forName(name, initialize=true, classLoader) en readClassDescriptor activa el inicializador estático de clases en la lista de permitidos\n\nEvaluación: Completamente abordado.\n\nPara CUALQUIER clase en la lista de permitidos, la deserialización de un flujo que la nombra activa el (inicializador estático) de la clase ANTES de que se construya cualquier instancia. Esto significa que un atacante que proporciona un nombre de clase en la lista de permitidos (por ejemplo, el desarrollador escribió accept('com.myapp.*'), el atacante proporciona com.myapp.SomeClass) causa <clinit> de SomeClass, y muchas clases del mundo real tienen inicializadores estáticos con efectos secundarios.\n\nAmbos problemas han sido solucionados."
}
],
"lastModified": "2026-07-22T19:10:00.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:mina:2.0.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7C9601B-0E76-4A86-A8A6-22E4AA6E5FA3"
},
{
"criteria": "cpe:2.3:a:apache:mina:2.1.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37EA09C2-6187-4BFD-BC22-1E7122EBA7CC"
},
{
"criteria": "cpe:2.3:a:apache:mina:2.2.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AA5D6AA-5F08-43CD-A493-7539D53AA33B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}