← العودة للجدول
CVE-2026-42778
CVE-2026-42778 — The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here
📅 2026-05-01
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.8 🎯 EPSS 0.26%

📋 الوصف الكامل

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are

💻 الأنظمة المتأثرة

Apache HTTP Server 2.4.x

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-42778

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.1.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←