CLEANSTART-2026-CR72646

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-CR72646.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-CR72646
Upstream
Published
2026-10-08T00:55:24Z
Modified
2026-10-08T16:46:41Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses
Details

Security vulnerability affects the apache-hive package. The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses.

References

Affected packages

CleanStart / apache-hive

Package

Name
apache-hive
Purl
pkg:apk/cleanstart/apache-hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-CR72646.json"