A vulnerability identified as critical has been detected in Apache MINA up to 2.0.27/2.1.10/2.2.5. This issue affects the function AbstractIoBuffer.resolveClass of the component acceptMatchers Filter. Performing a manipulation results in deserialization.

This vulnerability is identified as CVE-2026-41635. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.