CVE-2026-47321

EUVD-2026-83858
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.

Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.




The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)




For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:




public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.




Here are the additional constructor:






public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,



            final int compressionLevel, final int maxDecompressedSize,



            final long maxDecompressRatio, final long decompressRatioMinSize)








Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:






 CompressionFilter compressionFilter = new CompressionFilter()

                                                .setCompressionLevel(Zlib.COMPRESSION_MAX)

                                                .setMaxDecompressedSize(1_000_000)

                                                .setMaxDecompressRatio(100).

                                                .setDecompressRatioMinSize(100_000); 









Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.
Data Amplification
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
apacheCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.84%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
apachemina
2.2.0 ≤
𝑥
< 2.2.8
CNA
apachemina
2.1.0 ≤
𝑥
< 2.1.13
CNA
apachemina
2.0.0 ≤
𝑥
< 2.0.29
CNA
Debian logo
Debian Releases
Debian Product
Codename
mina
bookworm
no-dsa
bullseye
postponed
mina2
bookworm
no-dsa
bullseye
postponed
forky
2.2.9-1
fixed
sid
2.2.9-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mina
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne
xenial
needs-triage
mina2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage