Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate
Published Sep 21, 2026
7.5
HIGHCVSS 3.1
EPSS 0.49%
Description
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.
Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.
The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)
For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:
public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.
Here are the additional constructor:
public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,
final int compressionLevel, final int maxDecompressedSize,
final long maxDecompressRatio, final long decompressRatioMinSize)
Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:
CompressionFilter compressionFilter = new CompressionFilter()
.setCompressionLevel(Zlib.COMPRESSION_MAX)
.setMaxDecompressedSize(1_000_000)
.setMaxDecompressRatio(100).
.setDecompressRatioMinSize(100_000);
Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.
Affected products
-
- Version 2.0.0StatusaffectedConstraints<2.0.29
- Version 2.1.0StatusaffectedConstraints<2.1.13
- Version 2.2.0StatusaffectedConstraints<2.2.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache MINA | unaffected |
|
No data.
No data.
OpenShift Developer Tools and Services
jenkins
Affected
OpenShift Developer Tools and Services
jenkins-2-plugins
Affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Affected
Red Hat Enterprise Linux 10
maven-wagon
Affected
Red Hat Enterprise Linux 8
javapackages-tools:201801/maven-wagon
Affected
Red Hat Enterprise Linux 9
maven-wagon
Affected
Red Hat Enterprise Linux 9
maven:3.9/maven-wagon
Affected
Red Hat Fuse 7
mina-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Affected | n/a |
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux 10 | maven-wagon | Affected | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/maven-wagon | Affected | n/a |
| Red Hat Enterprise Linux 9 | maven-wagon | Affected | n/a |
| Red Hat Enterprise Linux 9 | maven:3.9/maven-wagon | Affected | n/a |
| Red Hat Fuse 7 | mina-core | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- http://www.openwall.com/lists/oss-security/2026/09/21/1
- https://access.redhat.com/security/cve/CVE-2026-47321 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2538436 Issue Tracking
- https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj mailing-listvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47321
- https://www.cve.org/CVERecord?id=CVE-2026-47321
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/21/1 | ||
| https://access.redhat.com/security/cve/CVE-2026-47321 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2538436 | Issue Tracking | |
| https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj | mailing-listvendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-47321 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-47321 |
Change history (0)
No recorded changes yet.