Description
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.

Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.




The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)




For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:




public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.




Here are the additional constructor:






public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,



final int compressionLevel, final int maxDecompressedSize,



final long maxDecompressRatio, final long decompressRatioMinSize)








Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:






 CompressionFilter compressionFilter = new CompressionFilter()

    .setCompressionLevel(Zlib.COMPRESSION_MAX)

  .setMaxDecompressedSize(1_000_000)

  .setMaxDecompressRatio(100).

  .setDecompressRatioMinSize(100_000); 









Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.
Published: 2026-09-21
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Apply Patch
AI Analysis

Impact

The CompressionFilter class in Apache MINA incorrectly handles inflating compressed data, allowing an attacker to send input that expands to a size far greater than the original. This lack of checking can cause the application to allocate an unbounded amount of memory, potentially exhausting system resources and causing a crash or service unavailability. The flaw maps to boundary and memory allocation weaknesses, noted as CWE-409 and CWE-789.

Affected Systems

Apache Software Foundation’s Apache MINA is affected, but specific version numbers are not provided in the advisory. Since the issue resides in the library, any application that integrates the CompressionFilter component is susceptible without version information available to verify patch status.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is through network traffic containing maliciously compressed payloads; the exploit requires an endpoint that accepts compressed data, making it a remote network-based denial-of-service attack.

Generated by OpenCVE AI on September 21, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache MINA to the latest release that includes the fixed CompressionFilter implementation
  • Configure the CompressionFilter to enforce limits by setting maxDecompressedSize and, if desired, maxDecompressRatio and decompressRatioMinSize using the available constructor or fluent API
  • Apply additional application‑level controls such as rate limiting or firewall rules to reduce the impact of potential DoS attempts

Generated by OpenCVE AI on September 21, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache mina
Vendors & Products Apache
Apache mina

Mon, 21 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size. The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes) For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize: public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted. Here are the additional constructor: public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize, final long maxDecompressRatio, final long decompressRatioMinSize) Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:  CompressionFilter compressionFilter = new CompressionFilter()     .setCompressionLevel(Zlib.COMPRESSION_MAX)   .setMaxDecompressedSize(1_000_000)   .setMaxDecompressRatio(100).   .setDecompressRatioMinSize(100_000);  Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.
Title Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate
Weaknesses CWE-409
CWE-789
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-21T07:43:24.769Z

Reserved: 2026-05-19T07:41:55.668Z

Link: CVE-2026-47321

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T08:16:37.520

Modified: 2026-09-21T08:16:37.520

Link: CVE-2026-47321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:00:12Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)

  • CWE-789

    Memory Allocation with Excessive Size Value