{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "mina"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "mina2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "mina2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "mina2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.2.9-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy   Assessment: Fully addressed.   When the serialised stream contains a TC_PROXYCLASSDESC (the marker  for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc()  is dispatched. JDK then calls the default  ObjectInputStream.resolveProxyClass(interfaces) implementation, which  performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH  interface name and constructs the proxy class â€” bypassing the accepted  classes list .   ZDRES-233: Class.forName(name, initialize=true, classLoader) in  readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes   Assessment: Fully addressed.   For ANY class on the allow-list, deserialising a stream that names it triggers the class’s   (static initialiser) BEFORE any instance is constructed. This means an  attacker who supplies a class name on the allow-list (e.g., the  developer wrote accept(“com.myapp.*\") , attacker supplies  com.myapp.SomeClass ) causes \u003cclinit\u003e of SomeClass â€” and many  real-world classes have side-effecting static initialisers   Both issues have been fixed.",
  "id": "DEBIAN-CVE-2026-47065",
  "modified": "2026-09-14T16:47:32.676309496Z",
  "published": "2026-06-03T11:16:19.800Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-47065"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-47065"
  ]
}