---
id: CVE-2026-84218
aliases:
  - GHSA-c9ff-59g8-m36q
title: >-
  jolokia-service-jsr160 Incomplete target JMX Service URL deny list handling
  for user-controlled input
summary: >-
  jolokia-service-jsr160 Incomplete target JMX Service URL deny list handling
  for user-controlled input
severity: high
cvss: 7.5
cwe:
  - CWE-184
vendor: jolokia
product: 'org.jolokia:jolokia-service-jsr160'
ecosystem: maven
affected:
  - 'org.jolokia:jolokia-service-jsr160 < 2.6.2'
patched:
  - 'org.jolokia:jolokia-service-jsr160 2.6.2'
published: '2026-09-01'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:04:16Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-c9ff-59g8-m36q'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84218'
  - url: 'https://github.com/jolokia/jolokia/issues/1049'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-84218'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2526752'
  - url: 'https://github.com/advisories/GHSA-c9ff-59g8-m36q'
  - url: 'https://jolokia.org/#jolokia_2_6_2_released_with_security_fixes'
tags:
  - ghsa
  - maven
epss: 0.00949
epssPercentile: 0.60003
ingestedAt: '2026-10-07T18:42:20.894Z'
---

## Overview

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.

## Affected packages

- `org.jolokia:jolokia-service-jsr160 < 2.6.2`

## Remediation

Upgrade to a patched release:

- `org.jolokia:jolokia-service-jsr160 2.6.2`
