CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-47065

Critical · CVSS 9.8

Apache (Java deserialization filter library — likely Apache Commons IO / SerialKiller / similar acceptMatchers-based filter) — Java deserialization filter bypass via resolveProxyClass not overridden and static initializer trigger (CWE-502)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-502

Description

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list . ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes Assessment: Fully addressed. For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*") , attacker supplies com.myapp.SomeClass ) causes <clinit> of SomeClass — and many real-world classes have side-effecting static initialisers Both issues have been fixed.

Search profile — drives PoC discovery

Symbols resolveProxyClassacceptMatchersTC_PROXYCLASSDESCreadProxyDescreadClassDescriptorClass.forNamelatestUserDefinedLoaderObjectInputStreamjava.lang.reflect.Proxy<clinit>accept
Keywords CVE-2026-47065ZDRES-232ZDRES-233resolveProxyClass not overriddenacceptMatchers filter bypassTC_PROXYCLASSDESC deserialization bypassJava proxy class deserializationstatic initializer deserializationreadProxyDesc bypassallow-list bypass deserializationjava deserialization proxy filter bypassapache deserialization filter CVE-2026-47065
Versions: <UNKNOWN>

Affected packages

Maven org.apache.mina:mina-core 0 → 2.0.29
Maven org.apache.mina:mina-core 2.1.0 → 2.1.13
Maven org.apache.mina:mina-core 2.2.0 → 2.2.8

References

Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T12:30:14.000Z