---
id: CVE-2026-47321
title: >-
  The CompressionFilter class uses ZLib to deflate and inflate data sent and
  received
summary: >-
  The CompressionFilter class uses ZLib to deflate and inflate data sent and
  received. When we inflate incoming data, the filter does not control the
  resulting size, and create a buffer no matter what.


  Some compressed data may have a comp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-409
  - CWE-789
vendor: Apache Software Foundation
product: 'org.apache.mina:mina-filter-compression'
affected:
  - 'org.apache.mina:mina-filter-compression >= 2.2.0 < 2.2.8'
  - 'org.apache.mina:mina-filter-compression >= 2.1.0 < 2.1.13'
  - 'org.apache.mina:mina-filter-compression >= 2.0.0 < 2.0.29'
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:06.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47321'
references:
  - url: 'https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/21/1'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00308
epssPercentile: 0.23835
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T14:00:30.976651Z'
ingestedAt: '2026-09-21T08:33:58.335Z'
---

## Overview

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.

Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.




The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)




For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:




public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.




Here are the additional constructor:






public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,



            final int compressionLevel, final int maxDecompressedSize,



            final long maxDecompressRatio, final long decompressRatioMinSize)








Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:






 CompressionFilter compressionFilter = new CompressionFilter()

                                                .setCompressionLevel(Zlib.COMPRESSION_MAX)

                                                .setMaxDecompressedSize(1_000_000)

                                                .setMaxDecompressRatio(100).

                                                .setDecompressRatioMinSize(100_000); 









Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
