A vulnerability labeled as critical has been found in Apache MINA up to 2.1.11/2.2.6. Impacted is the function
AbstractIoBuffer.resolveClass. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-42779. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.