Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-52046

46
FAUCET Score

CVE-2024-52046 is a critical deserialization vulnerability in Apache MINA core versions 2.0.X, 2.1.X, and 2.2.X, specifically within the ObjectSerializationDecoder. This flaw allows unauthenticated attackers to achieve Remote Code Execution (RCE) by sending specially crafted malicious serialized data, earning a CVSS score of 9.8 (CRITICAL). While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) is currently reported, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness. Mitigation requires upgrading to MINA core versions 2.0.27, 2.1.10, or 2.2.4 and explicitly configuring accepted classes for deserialization.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.0.27CPE matchmatch criteria
cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:*
>= 2.1.0, < 2.1.10CPE matchmatch criteria
cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:*
>= 2.2.0, < 2.2.4CPE matchmatch criteria
cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

10.0CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
23.93%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.2393 is in the 94th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

mavenpatch availablevia ghsa
Product: org.apache.mina:mina-coreFixed in: 2.0.27
mavenpatch availablevia ghsa
Product: org.apache.mina:mina-coreFixed in: 2.2.4
mavenpatch availablevia ghsa
Product: org.apache.mina:mina-coreFixed in: 2.1.10
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.8.3 for Spring BootFixed in: org.apache.mina/mina-core
View patch
redhatno patchvia redhat_api
Product: A-MQ Clients 2Fixed in: org.apache.mina/mina-core
redhatno patchvia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: org.apache.mina/mina-core
redhatend of lifevia redhat_api
Product: streams for Apache KafkaFixed in: org.apache.mina/mina-core
redhatend of lifevia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: org.apache.mina/mina-core
redhatend of lifevia redhat_api
Product: Red Hat Build of KeycloakFixed in: org.apache.mina/mina-core
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: org.apache.mina/mina-core
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: org.apache.mina/mina-core

Vendor Advisories (2)

mavenGHSA-76h9-2vwh-w278critical

Apache MINA Deserialization RCE Vulnerability

Dec 25, 2024
redhatCVE-2024-52046Important

mina-core: Apache MINA: applications using unbounded deserialization may allow RCE

Dec 25, 2024

References

security.netapp.com / advisory/ntap-20250103-0001
Third Party Advisory
openwall.com / lists/oss-security/2024/12/25/1
Mailing List
lists.apache.org / thread/4wxktgjpggdbto15d515wdctohb0qmv8
Mailing List