{"id":"CVE-2026-47321","title":"The CompressionFilter class uses ZLib to deflate and inflate data sent and received","summary":"The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.\n\nSome compressed data may have a comp…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-409","CWE-789"],"vendor":"Apache Software Foundation","product":"org.apache.mina:mina-filter-compression","affected":["org.apache.mina:mina-filter-compression >= 2.2.0 < 2.2.8","org.apache.mina:mina-filter-compression >= 2.1.0 < 2.1.13","org.apache.mina:mina-filter-compression >= 2.0.0 < 2.0.29"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T18:10:30.343","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47321","references":[{"url":"https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj","label":"security@apache.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T14:00:30.976651Z"},"epss":0.00291,"epssPercentile":0.21841,"ingestedAt":"2026-09-21T08:33:58.335Z","slug":"CVE-2026-47321","body":"## Overview\n\nThe CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.\n\nSome compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.\n\n\n\n\nThe fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)\n\n\n\n\nFor application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:\n\n\n\n\npublic CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.\n\n\n\n\nHere are the additional constructor:\n\n\n\n\n\n\npublic CompressionFilter(final boolean compressInbound, final boolean compressOutbound,\n\n\n\n            final int compressionLevel, final int maxDecompressedSize,\n\n\n\n            final long maxDecompressRatio, final long decompressRatioMinSize)\n\n\n\n\n\n\n\n\nAlso note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:\n\n\n\n\n\n\n CompressionFilter compressionFilter = new CompressionFilter()\n\n                                                .setCompressionLevel(Zlib.COMPRESSION_MAX)\n\n                                                .setMaxDecompressedSize(1_000_000)\n\n                                                .setMaxDecompressRatio(100).\n\n                                                .setDecompressRatioMinSize(100_000); \n\n\n\n\n\n\n\n\n\nApplications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}