Junglewise Threat Intelligence

CVE-2026-47321: Apache MINA CompressionFilter decompression bomb DoS

CVE-2026-47321 · Severity: high · CVSS 7.5 · Published 2026-09-21

Vendors: Apache.

Executive brief

Apache MINA's CompressionFilter class does not limit the size of data after decompression, allowing an attacker to send highly compressed payloads that expand to enormous sizes and exhaust application memory. This causes denial of service by crashing applications that process untrusted compressed data without proper safeguards.

Technical details

The CompressionFilter uses ZLib to decompress incoming data but fails to enforce limits on the decompressed output size or compression ratio, enabling decompression bomb attacks where small compressed inputs expand to gigabytes of data. An attacker can send a crafted compressed payload over the network to trigger uncontrolled memory allocation. The vulnerability is fixed by adding optional size and ratio limits via constructor parameters or a fluent API, with a 1MB grace threshold for small files.

Affected products

  • Apache MINA versions prior to fix

Timeline

  • 2026-09-21: disclosed

Related threats