This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/mina-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 4aa2626fa Updated site from master
(d55c72c3a1dfce476e126ac2a53b328f86b2e10f)
4aa2626fa is described below
commit 4aa2626faa296d58b3ec3599c23c23e979ee78fe
Author: jenkins <[email protected]>
AuthorDate: Fri May 1 02:20:19 2026 +0000
Updated site from master (d55c72c3a1dfce476e126ac2a53b328f86b2e10f)
---
content/downloads-mina_2_1.html | 26 +++++++-------
content/downloads-mina_2_2.html | 26 +++++++-------
content/index.xml | 18 ++++------
content/mina-project/downloads_2_1.html | 20 +++++------
content/mina-project/downloads_2_2.html | 22 ++++++------
content/mina-project/downloads_old.html | 10 ++++++
content/mina-project/gen-docs/.htaccess | 8 ++---
content/mina-project/index.html | 64 +++++++++++++++++++++++++++++++--
content/mina-project/index.xml | 14 +++-----
content/mina-project/news.html | 64 +++++++++++++++++++++++++++++++--
content/sitemap.xml | 14 ++++----
11 files changed, 204 insertions(+), 82 deletions(-)
diff --git a/content/downloads-mina_2_1.html b/content/downloads-mina_2_1.html
index 39528ddc8..84dfca671 100644
--- a/content/downloads-mina_2_1.html
+++ b/content/downloads-mina_2_1.html
@@ -103,18 +103,18 @@
<h1 id="latest-mina-releases">Latest MINA Releases</h1>
-<h2 id="apache-mina-2111-font-colorgreenstablefont-java-8">Apache MINA 2.1.11
<font color="green">stable</font> (Java 8+)</h2>
+<h2 id="apache-mina-2112-font-colorgreenstablefont-java-8">Apache MINA 2.1.12
<font color="green">stable</font> (Java 8+)</h2>
<h3 id="binaries">Binaries</h3>
<ul>
-<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.asc">ASC</a>)</li>
-<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.asc">ASC</a>)</li>
-<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.asc">ASC</a>)</li>
+<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.asc">ASC</a>)</li>
+<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.asc">ASC</a>)</li>
+<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.asc">ASC</a>)</li>
</ul>
<h3 id="sources">Sources</h3>
<ul>
-<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.asc">ASC</a>)</li>
-<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.asc">ASC</a>)</li>
-<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.zip">mina-2.1.11</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.asc">ASC</a>)</li>
+<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.asc">ASC</a>)</li>
+<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.asc">ASC</a>)</li>
+<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.zip">mina-2.1.12</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.asc">ASC</a>)</li>
</ul>
<div class="note" markdown="1">
For people wanting to use the <strong>serial</strong> package, we don't
include the <strong>rxtx.jar</strong> library in the releases, as it's under a
LGPL license. Please download it from <a
href="http://rxtx.qbang.org/wiki/index.php/Download" class="external-link"
rel="nofollow">http://rxtx.qbang.org/wiki/index.php/Download</a> or add the
associated dependency in your maven pom.xml :
@@ -129,28 +129,28 @@
<h1 id="verify-the-integrity-of-the-files">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<pre><code>$ pgpk -a KEYS
-$ pgpv mina-2.1.11.tar.gz.asc
+$ pgpv mina-2.1.12.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ pgp -ka KEYS
-$ pgp mina-2.1.11.tar.gz.asc
+$ pgp mina-2.1.12.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ gpg --import KEYS
-$ gpg --verify mina-2.1.11.tar.gz.asc
+$ gpg --verify mina-2.1.12.tar.gz.asc
</code></pre>
<h2 id="older-versions">Older versions</h2>
<p>Older versions can be found <a
href="https://archive.apache.org/dist/mina/">on
https://archive.apache.org/dist/mina/</a></p>
<h1 id="verify-the-integrity-of-the-files-1">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ pgpk -a KEYS
-$ pgpv mina-2.1.11.tar.gz.asc
+$ pgpv mina-2.1.12.tar.gz.asc
</code></pre></div><p>or</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ pgp -ka KEYS
-$ pgp mina-2.1.11.tar.gz.asc
+$ pgp mina-2.1.12.tar.gz.asc
</code></pre></div><p>or</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ gpg --import KEYS
-$ gpg --verify mina-2.1.11.tar.gz.asc
+$ gpg --verify mina-2.1.12.tar.gz.asc
</code></pre></div><p>Alternatively, you can verify the checksums of the files
(see the <a href="https://www.apache.org/info/verification.html">How to verify
downloaded files page</a>).</p>
<h1 id="previous-releases">Previous Releases</h1>
<p>The previous releases can be found on <a
href="https://archive.apache.org/dist/mina/">https://archive.apache.org/dist/mina/</a>.
Please note that the following releases contains a LGPL licensed file,
rxtx-2.1.8.jar: 2.0.0-M4, 2.0.0-M5, 2.0.0-M6, 2.0.0-RC1.</p>
diff --git a/content/downloads-mina_2_2.html b/content/downloads-mina_2_2.html
index e4bd3b7c8..f4a46c164 100644
--- a/content/downloads-mina_2_2.html
+++ b/content/downloads-mina_2_2.html
@@ -103,18 +103,18 @@
<h1 id="latest-mina-releases">Latest MINA Releases</h1>
-<h2 id="apache-mina-226-font-colorgreenstablefont-java-8">Apache MINA 2.2.6
<font color="green">stable</font> (Java 8+)</h2>
+<h2 id="apache-mina-227-font-colorgreenstablefont-java-8">Apache MINA 2.2.7
<font color="green">stable</font> (Java 8+)</h2>
<h3 id="binaries">Binaries</h3>
<ul>
-<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.asc">ASC</a>)</li>
-<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.asc">ASC</a>)</li>
-<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.asc">ASC</a>)</li>
+<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.asc">ASC</a>)</li>
+<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.asc">ASC</a>)</li>
+<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.asc">ASC</a>)</li>
</ul>
<h3 id="sources">Sources</h3>
<ul>
-<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.asc">ASC</a>)</li>
-<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.asc">ASC</a>)</li>
-<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.asc">ASC</a>)</li>
+<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.asc">ASC</a>)</li>
+<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.asc">ASC</a>)</li>
+<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.asc">ASC</a>)</li>
</ul>
<div class="note" markdown="1">
For people wanting to use the <strong>serial</strong> package, we don't
include the <strong>rxtx.jar</strong> library in the releases, as it's under a
LGPL license. Please download it from <a
href="http://rxtx.qbang.org/wiki/index.php/Download" class="external-link"
rel="nofollow">http://rxtx.qbang.org/wiki/index.php/Download</a> or add the
associated dependency in your maven pom.xml :
@@ -129,15 +129,15 @@
<h1 id="verify-the-integrity-of-the-files">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<pre><code>$ pgpk -a KEYS
-$ pgpv mina-2.2.6.tar.gz.asc
+$ pgpv mina-2.2.7.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ pgp -ka KEYS
-$ pgp mina-2.2.6.tar.gz.asc
+$ pgp mina-2.2.7.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ gpg --import KEYS
-$ gpg --verify mina-2.2.6.tar.gz.asc
+$ gpg --verify mina-2.2.7.tar.gz.asc
</code></pre>
<p>Alternatively, you can verify the checksums of the files (see the <a
href="https://www.apache.org/info/verification.html">How to verify downloaded
files page</a>).</p>
<h2 id="older-versions">Older versions</h2>
@@ -145,13 +145,13 @@ $ gpg --verify mina-2.2.6.tar.gz.asc
<h1 id="verify-the-integrity-of-the-files-1">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ pgpk -a KEYS
-$ pgpv mina-2.2.6.tar.gz.asc
+$ pgpv mina-2.2.7.tar.gz.asc
</code></pre></div><p>or</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ pgp -ka KEYS
-$ pgp mina-2.2.6.tar.gz.asc
+$ pgp mina-2.2.7.tar.gz.asc
</code></pre></div><p>or</p>
<div class="highlight"><pre
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4"><code
class="language-bash" data-lang="bash">$ gpg --import KEYS
-$ gpg --verify mina-2.2.6.tar.gz.asc
+$ gpg --verify mina-2.2.7.tar.gz.asc
</code></pre></div><h1 id="previous-releases">Previous Releases</h1>
<p>The previous releases can be found on <a
href="https://archive.apache.org/dist/mina/">https://archive.apache.org/dist/mina/</a>.
Please note that the following releases contains a LGPL licensed file,
rxtx-2.1.7.jar: 2.0.0-M4, 2.0.0-M5, 2.0.0-M6, 2.0.0-RC1.</p>
<h1 id="version-numbering-scheme">Version Numbering Scheme</h1>
diff --git a/content/index.xml b/content/index.xml
index 37582dc40..9cf3d2e24 100644
--- a/content/index.xml
+++ b/content/index.xml
@@ -1862,7 +1862,7 @@ What are the important information you need to put when
filing a JIRA ?</descrip
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_2_1.html</guid>
- <description>Latest MINA Releases Apache MINA 2.1.11 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.11 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.11 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
+ <description>Latest MINA Releases Apache MINA 2.1.12 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.12 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.12 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
</item>
<item>
@@ -1881,7 +1881,7 @@ It was decided to change that and make it easier for the
application to get this
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_2_2.html</guid>
- <description>Latest MINA Releases Apache MINA 2.2.6 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.6 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.6 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
+ <description>Latest MINA Releases Apache MINA 2.2.7 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.7 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.7 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
</item>
<item>
@@ -1912,7 +1912,7 @@ The Codecs listed here may not be part of Apache MINA
project. The information i
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/downloads-mina_2_1.html</guid>
- <description>Latest MINA Releases Apache MINA 2.1.11 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.11 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.11 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
+ <description>Latest MINA Releases Apache MINA 2.1.12 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.12 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.12 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
</item>
<item>
@@ -1921,7 +1921,7 @@ The Codecs listed here may not be part of Apache MINA
project. The information i
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/downloads-mina_2_2.html</guid>
- <description>Latest MINA Releases Apache MINA 2.2.6 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.6 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.6 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
+ <description>Latest MINA Releases Apache MINA 2.2.7 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.7 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.7 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
</item>
<item>
@@ -1941,7 +1941,7 @@ Apache MINA is often called:
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_old.html</guid>
- <description>Older MINA Releases For people wanting to use the serial
package, we don't include the rxtx.jar library in the releases, as it's
under a LGPL license. Please download it from
http://rxtx.qbang.org/wiki/index.php/Download or add the associated dependency
in your maven pom.xml : &lt;dependency&gt;
&lt;groupId&gt;org.rxtx&lt;/groupId&gt;
&lt;artifactId&gt;rxtx&lt;/artifactId&gt;
&lt;version&gt;2.1.7&lt;/version&a [...]
+ <description>Older MINA Releases For people wanting to use the serial
package, we don't include the rxtx.jar library in the releases, as it's
under a LGPL license. Please download it from
http://rxtx.qbang.org/wiki/index.php/Download or add the associated dependency
in your maven pom.xml : &lt;dependency&gt;
&lt;groupId&gt;org.rxtx&lt;/groupId&gt;
&lt;artifactId&gt;rxtx&lt;/artifactId&gt;
&lt;version&gt;2.1.7&lt;/version&a [...]
</item>
<item>
@@ -1960,12 +1960,8 @@ Apache MINA is often called:
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/news.html</guid>
- <description>News MINA 2.2.6, 2.1.11, 2.0.28 released posted on April,
27 2026 The MINA project is pleased to announce the MINA 2.2.6, 2.1.11 and
2.0.28 release.
-This issue fixes two critical security issues:
-CVE-2026-41409 MINA applications using unbounded deserialization may allow RCE.
-Affected versions:
- Apache MINA 2.0 through 2.0.27 Apache MINA 2.1 through 2.1.10 Apache MINA 2.2
through 2.2.5 Description:
-The ObjectSerializationDecoder in Apache MINA uses Java native deserialization
protocol to process incoming serialized data but lacks the necessary security
checks and defenses.</description>
+ <description>News MINA 2.2.7, 2.1.12 released posted on April, 30 2026
The MINA project is pleased to announce the MINA 2.2.7 and 2.1.12 release.
+This issue fixes two critical security issues, which were expected to have
been fixed by the previous release. Sadly the code change that was supposed to
be applied to the three versions was only applied to the 2.0.X branch, leaving
2.2.6 and 2.1.11 in the same state than before.</description>
</item>
<item>
diff --git a/content/mina-project/downloads_2_1.html
b/content/mina-project/downloads_2_1.html
index 1374b5636..45a88dfe4 100644
--- a/content/mina-project/downloads_2_1.html
+++ b/content/mina-project/downloads_2_1.html
@@ -123,18 +123,18 @@
<h1 id="latest-mina-releases">Latest MINA Releases</h1>
-<h2 id="apache-mina-2111-font-colorgreenstablefont-java-8">Apache MINA 2.1.11
<font color="green">stable</font> (Java 8+)</h2>
+<h2 id="apache-mina-2112-font-colorgreenstablefont-java-8">Apache MINA 2.1.12
<font color="green">stable</font> (Java 8+)</h2>
<h3 id="binaries">Binaries</h3>
<ul>
-<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.gz.asc">ASC</a>)</li>
-<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.tar.bz2.asc">ASC</a>)</li>
-<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-bin.zip.asc">ASC</a>)</li>
+<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.gz.asc">ASC</a>)</li>
+<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.tar.bz2.asc">ASC</a>)</li>
+<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-bin.zip.asc">ASC</a>)</li>
</ul>
<h3 id="sources">Sources</h3>
<ul>
-<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.gz.asc">ASC</a>)</li>
-<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.tar.bz2.asc">ASC</a>)</li>
-<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.11/apache-mina-2.1.11-src.zip">mina-2.1.11</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.11/apache-mina-2.1.11-src.zip.asc">ASC</a>)</li>
+<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.gz.asc">ASC</a>)</li>
+<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.tar.bz2.asc">ASC</a>)</li>
+<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.1.12/apache-mina-2.1.12-src.zip">mina-2.1.12</a>
(signatures : <a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.sha256">SHA256</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.sha512">SHA512</a>
<a
href="https://www.apache.org/dist/mina/mina/2.1.12/apache-mina-2.1.12-src.zip.asc">ASC</a>)</li>
</ul>
<div class="note" markdown="1">
For people wanting to use the <strong>serial</strong> package, we don't
include the <strong>rxtx.jar</strong> library in the releases, as it's under a
LGPL license. Please download it from <a
href="http://rxtx.qbang.org/wiki/index.php/Download" class="external-link"
rel="nofollow">http://rxtx.qbang.org/wiki/index.php/Download</a> or add the
associated dependency in your maven pom.xml :
@@ -149,15 +149,15 @@
<h1 id="verify-the-integrity-of-the-files">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<pre><code>$ pgpk -a KEYS
-$ pgpv mina-2.1.11.tar.gz.asc
+$ pgpv mina-2.1.12.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ pgp -ka KEYS
-$ pgp mina-2.1.11.tar.gz.asc
+$ pgp mina-2.1.12.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ gpg --import KEYS
-$ gpg --verify mina-2.1.11.tar.gz.asc
+$ gpg --verify mina-2.1.12.tar.gz.asc
</code></pre>
<p>Alternatively, you can verify the checksums of the files (see the <a
href="https://www.apache.org/info/verification.html">How to verify downloaded
files page</a>).</p>
<h1 id="previous-releases">Previous Releases</h1>
diff --git a/content/mina-project/downloads_2_2.html
b/content/mina-project/downloads_2_2.html
index eb06e5cce..7175901b5 100644
--- a/content/mina-project/downloads_2_2.html
+++ b/content/mina-project/downloads_2_2.html
@@ -123,18 +123,18 @@
<h1 id="latest-mina-releases">Latest MINA Releases</h1>
-<h2 id="apache-mina-226-font-colorgreenstablefont-java-8">Apache MINA 2.2.6
<font color="green">stable</font> (Java 8+)</h2>
+<h2 id="apache-mina-227-font-colorgreenstablefont-java-8">Apache MINA 2.2.7
<font color="green">stable</font> (Java 8+)</h2>
<h3 id="binaries">Binaries</h3>
<ul>
-<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.gz.asc">ASC</a>)</li>
-<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.tar.bz2.asc">ASC</a>)</li>
-<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-bin.zip.asc">ASC</a>)</li>
+<li>.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.gz.asc">ASC</a>)</li>
+<li>.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.tar.bz2.asc">ASC</a>)</li>
+<li>.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-bin.zip.asc">ASC</a>)</li>
</ul>
<h3 id="sources">Sources</h3>
<ul>
-<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.gz.asc">ASC</a>)</li>
-<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.tar.bz2.asc">ASC</a>)</li>
-<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip">mina-2.2.6</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.6/apache-mina-2.2.6-src.zip.asc">ASC</a>)</li>
+<li>.src.tar.gz archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.gz.asc">ASC</a>)</li>
+<li>.src.tar.bz2 archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.tar.bz2.asc">ASC</a>)</li>
+<li>.src.zip archive <a
href="https://dlcdn.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip">mina-2.2.7</a>
(signatures : <a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.sha256">SHA256</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.sha512">SHA512</a>
<a
href="https://downloads.apache.org/mina/mina/2.2.7/apache-mina-2.2.7-src.zip.asc">ASC</a>)</li>
</ul>
<div class="note" markdown="1">
For people wanting to use the <strong>serial</strong> package, we don't
include the <strong>rxtx.jar</strong> library in the releases, as it's under a
LGPL license. Please download it from <a
href="http://rxtx.qbang.org/wiki/index.php/Download" class="external-link"
rel="nofollow">http://rxtx.qbang.org/wiki/index.php/Download</a> or add the
associated dependency in your maven pom.xml :
@@ -149,15 +149,15 @@
<h1 id="verify-the-integrity-of-the-files">Verify the integrity of the
files</h1>
<p>The PGP signatures can be verified using PGP or GPG. First download the <a
href="https://downloads.apache.org/mina/KEYS">KEYS</a> as well as the asc
signature file for the relevant distribution. Then verify the signatures
using:</p>
<pre><code>$ pgpk -a KEYS
-$ pgpv mina-2.2.6.tar.gz.asc
+$ pgpv mina-2.2.7.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ pgp -ka KEYS
-$ pgp mina-2.2.6.tar.gz.asc
+$ pgp mina-2.2.7.tar.gz.asc
</code></pre>
<p>or</p>
<pre><code>$ gpg --import KEYS
-$ gpg --verify mina-2.2.6.tar.gz.asc
+$ gpg --verify mina-2.2.7.tar.gz.asc
</code></pre>
<p>Alternatively, you can verify the checksums of the files (see the <a
href="https://www.apache.org/info/verification.html">How to verify downloaded
files page</a>).</p>
<h1 id="previous-releases">Previous Releases</h1>
@@ -182,7 +182,7 @@ $ gpg --verify mina-2.2.6.tar.gz.asc
<p>MINA is not a stand-alone software, so ‘the feature set’ here
also includes the API of the newly introduced features and the overall
architecture of the software,</p>
<p>Here’s an example that illustrates how MINA version number
increases:</p>
<div class="info" markdown="1">
- 2.0.0-M1 -> 2.0.0-M3 -> 2.0.0-M3 -> 2.0.0-M4 -> 2.0.0-RC1 -> 2.0.0-RC2 ->
2.0.0-RC3 -> <strong>2.0.0</strong> -> 2.0.1 -> 2.0.2 -> 2.2.6-M1 ...
+ 2.0.0-M1 -> 2.0.0-M3 -> 2.0.0-M3 -> 2.0.0-M4 -> 2.0.0-RC1 -> 2.0.0-RC2 ->
2.0.0-RC3 -> <strong>2.0.0</strong> -> 2.0.1 -> 2.0.2 -> 2.2.7-M1 ...
</div>
<p>Please note that we always specify the micro number, even if it’s
zero.</p>
diff --git a/content/mina-project/downloads_old.html
b/content/mina-project/downloads_old.html
index 439ef46a3..93c7c1335 100644
--- a/content/mina-project/downloads_old.html
+++ b/content/mina-project/downloads_old.html
@@ -145,6 +145,11 @@
</thead>
<tbody>
<tr>
+<td align="center">ApacheDS MINA 2.2.6</td>
+<td align="center"><a
href="https://archive.apache.org/dist/mina/mina/2.2.6/">Download</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.2.6/apidocs/index.html">Javadoc</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.2.6/testapidocs/index.html">Test
javadoc</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.2.6/xref/index.html">Xref</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.2.6/xref-test/index.html">Xref
test</a></td>
+<td align="center">27/Apr/2026</td>
+</tr>
+<tr>
<td align="center">ApacheDS MINA 2.2.5</td>
<td align="center"><a
href="https://archive.apache.org/dist/mina/mina/2.2.5/">Download</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.2.5/apidocs/index.html">Javadoc</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.2.5/testapidocs/index.html">Test
javadoc</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.2.5/xref/index.html">Xref</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.2.5/xref-test/index.html">Xref
test</a></td>
<td align="center">28/Nov/2025</td>
@@ -188,6 +193,11 @@
</thead>
<tbody>
<tr>
+<td align="center">ApacheDS MINA 2.1.11</td>
+<td align="center"><a
href="https://archive.apache.org/dist/mina/mina/2.1.11/">Download</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.1.11/apidocs/index.html">Javadoc</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.1.11/testapidocs/index.html">Test
javadoc</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.1.11/xref/index.html">Xref</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.1.11/xref-test/index.html">Xref
test</a></td>
+<td align="center">27/Apr/2026</td>
+</tr>
+<tr>
<td align="center">ApacheDS MINA 2.1.10</td>
<td align="center"><a
href="https://archive.apache.org/dist/mina/mina/2.1.10/">Download</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.1.10/apidocs/index.html">Javadoc</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.1.10/testapidocs/index.html">Test
javadoc</a>, <a
href="https://mina.apache.org/mina-project/gen-docs/2.1.10/xref/index.html">Xref</a>,
<a
href="https://mina.apache.org/mina-project/gen-docs/2.1.10/xref-test/index.html">Xref
test</a></td>
<td align="center">24/Dec/2024</td>
diff --git a/content/mina-project/gen-docs/.htaccess
b/content/mina-project/gen-docs/.htaccess
index e20898a45..437555b70 100644
--- a/content/mina-project/gen-docs/.htaccess
+++ b/content/mina-project/gen-docs/.htaccess
@@ -5,11 +5,11 @@ RewriteEngine On
RewriteRule ^latest-2.0$ https://nightlies.apache.org/mina/mina/2.0.28/ [QSA,L]
RewriteRule ^latest-2.0/(.*)$ https://nightlies.apache.org/mina/mina/2.0.28/$1
[QSA,L]
-RewriteRule ^latest-2.1$ https://nightlies.apache.org/mina/mina/2.1.11/ [QSA,L]
-RewriteRule ^latest-2.1/(.*)$ https://nightlies.apache.org/mina/mina/2.1.11/$1
[QSA,L]
+RewriteRule ^latest-2.1$ https://nightlies.apache.org/mina/mina/2.1.12/ [QSA,L]
+RewriteRule ^latest-2.1/(.*)$ https://nightlies.apache.org/mina/mina/2.1.12/$1
[QSA,L]
-RewriteRule ^latest-2.2$ https://nightlies.apache.org/mina/mina/2.2.6/ [QSA,L]
-RewriteRule ^latest-2.2/(.*)$ https://nightlies.apache.org/mina/mina/2.2.6/$1
[QSA,L]
+RewriteRule ^latest-2.2$ https://nightlies.apache.org/mina/mina/2.2.7/ [QSA,L]
+RewriteRule ^latest-2.2/(.*)$ https://nightlies.apache.org/mina/mina/2.2.7/$1
[QSA,L]
# Redirect everything else
RewriteRule ^(.*)$ https://nightlies.apache.org/mina/mina/$1 [QSA,L]
diff --git a/content/mina-project/index.html b/content/mina-project/index.html
index 195efe608..11867998c 100644
--- a/content/mina-project/index.html
+++ b/content/mina-project/index.html
@@ -136,6 +136,66 @@
<div class="news">
<h1 id="news">News</h1>
+<h2 id="mina-227-2112-released-_posted-on-april-30-2026_">MINA 2.2.7, 2.1.12
released <em>posted on April, 30 2026</em></h2>
+<p>The MINA project is pleased to announce the MINA 2.2.7 and 2.1.12
release.</p>
+<p>This issue fixes two critical security issues, which were expected to have
been fixed by the previous release. Sadly the code change that was supposed to
be applied to the three versions was only applied to the 2.0.X branch, leaving
2.2.6 and 2.1.11 in the same state than before. These new releases correct this
mistake.</p>
+<h3 id="cve-2026-42778httpswwwcveorgcverecordidcve-2026-42778"><a
href="https://www.cve.org/CVERecord?id=CVE-2026-42778">CVE-2026-42778</a></h3>
+<p>Note: this is the exact same CVE than <em>CVE-2026-41409</em></p>
+<p><strong>MINA</strong> applications using unbounded deserialization may
allow <strong>RCE</strong>.</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache MINA 2.1 through 2.1.11</li>
+<li>Apache MINA 2.2 through 2.2.6</li>
+</ul>
+<p>Description:</p>
+<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process
+incoming serialized data but lacks the necessary security checks and defenses.
This vulnerability allows
+attackers to exploit the deserialization process by sending specially crafted
malicious serialized data,
+potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
+<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but it was applied too late for classes that have a static initializer
which get executed even for not allowed classes.</p>
+<h3 id="cve-2026-42779httpswwwcveorgcverecordidcve-2026-42779"><a
href="https://www.cve.org/CVERecord?id=CVE-2026-42779">CVE-2026-42779</a></h3>
+<p>Note: this is the exact same CVE than <em>CVE-2026-41635</em></p>
+<p><strong>MINA</strong> applications using unbounded deserialization may
allow <strong>RCE</strong>.</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache MINA 2.1 through 2.1.11</li>
+<li>Apache MINA 2.2 through 2.2.6</li>
+</ul>
+<p>Description:</p>
+<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process incoming
serialized data but lacks the necessary security checks and defenses. This
vulnerability allows attackers to exploit the deserialization process by
sending specially crafted malicious serialized data,
+potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
+<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but static classes or primitives types are bypassing this check.</p>
+<h2 id="versions-affected">Versions affected</h2>
+<p>These issues affects <strong>MINA</strong> core versions 2.1.X and 2.2.X,
and is fixed by the releases 2.1.12 and 2.2.7.</p>
+<h2 id="mitigation">Mitigation</h2>
+<p>It’s also important to note that an application using
<strong>MINA</strong> core library will only be affected if the
<em>IoBuffer#getObject()</em> method is called, and this specific method is
potentially called when adding a <em>ProtocolCodecFilter</em> instance using
the <em>ObjectSerializationCodecFactory</em> class in the filter chain. If your
application is specifically using those classes, you have to upgrade to the
latest version of <strong>MINA</strong> core library.</p>
+<p><strong>Upgrading will not be enough: you also need to explicitly allow
the classes the decoder will accept in the <em>ObjectSerializationDecoder</em>
instance, using one of the three new methods:</strong></p>
+<pre><code> /**
+ * Accept class names where the supplied ClassNameMatcher matches for
+ * deserialization, unless they are otherwise rejected.
+ *
+ * @param classNameMatcher the matcher to use
+ */
+ public void accept(ClassNameMatcher classNameMatcher)
+
+ /**
+ * Accept class names that match the supplied pattern for
+ * deserialization, unless they are otherwise rejected.
+ *
+ * @param pattern standard Java regexp
+ */
+ public void accept(Pattern pattern)
+
+ /**
+ * Accept the wildcard specified classes for deserialization,
+ * unless they are otherwise rejected.
+ *
+ * @param patterns Wildcard file name patterns as defined by
+ *
org.apache.commons.io.FilenameUtils#wildcardMatch(String, String)
+ */
+ public void accept(String... patterns)
+</code></pre><p>By default, the decoder will reject <em>all</em> classes that
will be present in the incoming data.</p>
+<p>Note: The <strong>FtpServer</strong>, <strong>SSHd</strong> and
<strong>Vysper</strong> sub-project are not affected by this issue.</p>
<h2 id="mina-226-2111-2028-released-_posted-on-april-27-2026_">MINA 2.2.6,
2.1.11, 2.0.28 released <em>posted on April, 27 2026</em></h2>
<p>The MINA project is pleased to announce the MINA 2.2.6, 2.1.11 and 2.0.28
release.</p>
<p>This issue fixes two critical security issues:</p>
@@ -165,9 +225,9 @@ potentially leading to remote code execution
(<strong>RCE</strong>) attacks.</p>
<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process incoming
serialized data but lacks the necessary security checks and defenses. This
vulnerability allows attackers to exploit the deserialization process by
sending specially crafted malicious serialized data,
potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but static classes or primitives types are bypassing this check.</p>
-<h2 id="versions-affected">Versions affected</h2>
+<h2 id="versions-affected-1">Versions affected</h2>
<p>These issues affects <strong>MINA</strong> core versions 2.0.X, 2.1.X and
2.2.X, and is fixed by the releases 2.0.28, 2.1.11 and 2.2.6.</p>
-<h2 id="mitigation">Mitigation</h2>
+<h2 id="mitigation-1">Mitigation</h2>
<p>It’s also important to note that an application using
<strong>MINA</strong> core library will only be affected if the
<em>IoBuffer#getObject()</em> method is called, and this specific method is
potentially called when adding a <em>ProtocolCodecFilter</em> instance using
the <em>ObjectSerializationCodecFactory</em> class in the filter chain. If your
application is specifically using those classes, you have to upgrade to the
latest version of <strong>MINA</strong> core library.</p>
<p><strong>Upgrading will not be enough: you also need to explicitly allow
the classes the decoder will accept in the <em>ObjectSerializationDecoder</em>
instance, using one of the three new methods:</strong></p>
<pre><code> /**
diff --git a/content/mina-project/index.xml b/content/mina-project/index.xml
index 4eba7b0f4..ccf6a5b39 100644
--- a/content/mina-project/index.xml
+++ b/content/mina-project/index.xml
@@ -681,7 +681,7 @@ What are the important information you need to put when
filing a JIRA ?</descrip
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_2_1.html</guid>
- <description>Latest MINA Releases Apache MINA 2.1.11 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.11 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.11
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.11 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.11 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
+ <description>Latest MINA Releases Apache MINA 2.1.12 stable (Java 8+)
Binaries .tar.gz archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.1.12 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.1.12
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.1.12 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.1.12 (signatures : SHA256 SHA512
ASC) For people wanting to [...]
</item>
<item>
@@ -700,7 +700,7 @@ It was decided to change that and make it easier for the
application to get this
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_2_2.html</guid>
- <description>Latest MINA Releases Apache MINA 2.2.6 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.6 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.6
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.6 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.6 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
+ <description>Latest MINA Releases Apache MINA 2.2.7 stable (Java 8+)
Binaries .tar.gz archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .tar.bz2
archive mina-2.2.7 (signatures : SHA256 SHA512 ASC) .zip archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) Sources .src.tar.gz archive mina-2.2.7
(signatures : SHA256 SHA512 ASC) .src.tar.bz2 archive mina-2.2.7 (signatures :
SHA256 SHA512 ASC) .src.zip archive mina-2.2.7 (signatures : SHA256 SHA512 ASC)
For people wanting to use th [...]
</item>
<item>
@@ -742,7 +742,7 @@ Apache MINA is often called:
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/downloads_old.html</guid>
- <description>Older MINA Releases For people wanting to use the serial
package, we don't include the rxtx.jar library in the releases, as it's
under a LGPL license. Please download it from
http://rxtx.qbang.org/wiki/index.php/Download or add the associated dependency
in your maven pom.xml : &lt;dependency&gt;
&lt;groupId&gt;org.rxtx&lt;/groupId&gt;
&lt;artifactId&gt;rxtx&lt;/artifactId&gt;
&lt;version&gt;2.1.7&lt;/version&a [...]
+ <description>Older MINA Releases For people wanting to use the serial
package, we don't include the rxtx.jar library in the releases, as it's
under a LGPL license. Please download it from
http://rxtx.qbang.org/wiki/index.php/Download or add the associated dependency
in your maven pom.xml : &lt;dependency&gt;
&lt;groupId&gt;org.rxtx&lt;/groupId&gt;
&lt;artifactId&gt;rxtx&lt;/artifactId&gt;
&lt;version&gt;2.1.7&lt;/version&a [...]
</item>
<item>
@@ -761,12 +761,8 @@ Apache MINA is often called:
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
<guid>https://mina.apache.org/mina-project/news.html</guid>
- <description>News MINA 2.2.6, 2.1.11, 2.0.28 released posted on April,
27 2026 The MINA project is pleased to announce the MINA 2.2.6, 2.1.11 and
2.0.28 release.
-This issue fixes two critical security issues:
-CVE-2026-41409 MINA applications using unbounded deserialization may allow RCE.
-Affected versions:
- Apache MINA 2.0 through 2.0.27 Apache MINA 2.1 through 2.1.10 Apache MINA 2.2
through 2.2.5 Description:
-The ObjectSerializationDecoder in Apache MINA uses Java native deserialization
protocol to process incoming serialized data but lacks the necessary security
checks and defenses.</description>
+ <description>News MINA 2.2.7, 2.1.12 released posted on April, 30 2026
The MINA project is pleased to announce the MINA 2.2.7 and 2.1.12 release.
+This issue fixes two critical security issues, which were expected to have
been fixed by the previous release. Sadly the code change that was supposed to
be applied to the three versions was only applied to the 2.0.X branch, leaving
2.2.6 and 2.1.11 in the same state than before.</description>
</item>
<item>
diff --git a/content/mina-project/news.html b/content/mina-project/news.html
index dea35a75d..17143ce13 100644
--- a/content/mina-project/news.html
+++ b/content/mina-project/news.html
@@ -123,6 +123,66 @@
<h1 id="news">News</h1>
+<h2 id="mina-227-2112-released-_posted-on-april-30-2026_">MINA 2.2.7, 2.1.12
released <em>posted on April, 30 2026</em></h2>
+<p>The MINA project is pleased to announce the MINA 2.2.7 and 2.1.12
release.</p>
+<p>This issue fixes two critical security issues, which were expected to have
been fixed by the previous release. Sadly the code change that was supposed to
be applied to the three versions was only applied to the 2.0.X branch, leaving
2.2.6 and 2.1.11 in the same state than before. These new releases correct this
mistake.</p>
+<h3 id="cve-2026-42778httpswwwcveorgcverecordidcve-2026-42778"><a
href="https://www.cve.org/CVERecord?id=CVE-2026-42778">CVE-2026-42778</a></h3>
+<p>Note: this is the exact same CVE than <em>CVE-2026-41409</em></p>
+<p><strong>MINA</strong> applications using unbounded deserialization may
allow <strong>RCE</strong>.</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache MINA 2.1 through 2.1.11</li>
+<li>Apache MINA 2.2 through 2.2.6</li>
+</ul>
+<p>Description:</p>
+<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process
+incoming serialized data but lacks the necessary security checks and defenses.
This vulnerability allows
+attackers to exploit the deserialization process by sending specially crafted
malicious serialized data,
+potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
+<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but it was applied too late for classes that have a static initializer
which get executed even for not allowed classes.</p>
+<h3 id="cve-2026-42779httpswwwcveorgcverecordidcve-2026-42779"><a
href="https://www.cve.org/CVERecord?id=CVE-2026-42779">CVE-2026-42779</a></h3>
+<p>Note: this is the exact same CVE than <em>CVE-2026-41635</em></p>
+<p><strong>MINA</strong> applications using unbounded deserialization may
allow <strong>RCE</strong>.</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache MINA 2.1 through 2.1.11</li>
+<li>Apache MINA 2.2 through 2.2.6</li>
+</ul>
+<p>Description:</p>
+<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process incoming
serialized data but lacks the necessary security checks and defenses. This
vulnerability allows attackers to exploit the deserialization process by
sending specially crafted malicious serialized data,
+potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
+<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but static classes or primitives types are bypassing this check.</p>
+<h2 id="versions-affected">Versions affected</h2>
+<p>These issues affects <strong>MINA</strong> core versions 2.1.X and 2.2.X,
and is fixed by the releases 2.1.12 and 2.2.7.</p>
+<h2 id="mitigation">Mitigation</h2>
+<p>It’s also important to note that an application using
<strong>MINA</strong> core library will only be affected if the
<em>IoBuffer#getObject()</em> method is called, and this specific method is
potentially called when adding a <em>ProtocolCodecFilter</em> instance using
the <em>ObjectSerializationCodecFactory</em> class in the filter chain. If your
application is specifically using those classes, you have to upgrade to the
latest version of <strong>MINA</strong> core library.</p>
+<p><strong>Upgrading will not be enough: you also need to explicitly allow
the classes the decoder will accept in the <em>ObjectSerializationDecoder</em>
instance, using one of the three new methods:</strong></p>
+<pre><code> /**
+ * Accept class names where the supplied ClassNameMatcher matches for
+ * deserialization, unless they are otherwise rejected.
+ *
+ * @param classNameMatcher the matcher to use
+ */
+ public void accept(ClassNameMatcher classNameMatcher)
+
+ /**
+ * Accept class names that match the supplied pattern for
+ * deserialization, unless they are otherwise rejected.
+ *
+ * @param pattern standard Java regexp
+ */
+ public void accept(Pattern pattern)
+
+ /**
+ * Accept the wildcard specified classes for deserialization,
+ * unless they are otherwise rejected.
+ *
+ * @param patterns Wildcard file name patterns as defined by
+ *
org.apache.commons.io.FilenameUtils#wildcardMatch(String, String)
+ */
+ public void accept(String... patterns)
+</code></pre><p>By default, the decoder will reject <em>all</em> classes that
will be present in the incoming data.</p>
+<p>Note: The <strong>FtpServer</strong>, <strong>SSHd</strong> and
<strong>Vysper</strong> sub-project are not affected by this issue.</p>
<h2 id="mina-226-2111-2028-released-_posted-on-april-27-2026_">MINA 2.2.6,
2.1.11, 2.0.28 released <em>posted on April, 27 2026</em></h2>
<p>The MINA project is pleased to announce the MINA 2.2.6, 2.1.11 and 2.0.28
release.</p>
<p>This issue fixes two critical security issues:</p>
@@ -152,9 +212,9 @@ potentially leading to remote code execution
(<strong>RCE</strong>) attacks.</p>
<p>The <em>ObjectSerializationDecoder</em> in Apache <strong>MINA</strong>
uses <strong>Java</strong> native deserialization protocol to process incoming
serialized data but lacks the necessary security checks and defenses. This
vulnerability allows attackers to exploit the deserialization process by
sending specially crafted malicious serialized data,
potentially leading to remote code execution (<strong>RCE</strong>)
attacks.</p>
<p>A security release has been issued in Decmber 2024, but was incomplete. An
allow-list of classes was added to tell MINA which classes can be used by the
deserialization of messages through the <em>AbstractIoBuffer.getObject()</em>
method, but static classes or primitives types are bypassing this check.</p>
-<h2 id="versions-affected">Versions affected</h2>
+<h2 id="versions-affected-1">Versions affected</h2>
<p>These issues affects <strong>MINA</strong> core versions 2.0.X, 2.1.X and
2.2.X, and is fixed by the releases 2.0.28, 2.1.11 and 2.2.6.</p>
-<h2 id="mitigation">Mitigation</h2>
+<h2 id="mitigation-1">Mitigation</h2>
<p>It’s also important to note that an application using
<strong>MINA</strong> core library will only be affected if the
<em>IoBuffer#getObject()</em> method is called, and this specific method is
potentially called when adding a <em>ProtocolCodecFilter</em> instance using
the <em>ObjectSerializationCodecFactory</em> class in the filter chain. If your
application is specifically using those classes, you have to upgrade to the
latest version of <strong>MINA</strong> core library.</p>
<p><strong>Upgrading will not be enough: you also need to explicitly allow
the classes the decoder will accept in the <em>ObjectSerializationDecoder</em>
instance, using one of the three new methods:</strong></p>
<pre><code> /**
diff --git a/content/sitemap.xml b/content/sitemap.xml
index 1a9b779f4..7d69bc60c 100644
--- a/content/sitemap.xml
+++ b/content/sitemap.xml
@@ -894,7 +894,7 @@
<url>
<loc>https://mina.apache.org/mina-project/downloads_2_1.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
@@ -904,7 +904,7 @@
<url>
<loc>https://mina.apache.org/mina-project/downloads_2_2.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
@@ -919,12 +919,12 @@
<url>
<loc>https://mina.apache.org/downloads-mina_2_1.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
<loc>https://mina.apache.org/downloads-mina_2_2.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
@@ -934,7 +934,7 @@
<url>
<loc>https://mina.apache.org/mina-project/downloads_old.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
@@ -944,12 +944,12 @@
<url>
<loc>https://mina.apache.org/mina-project.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>
<loc>https://mina.apache.org/mina-project/news.html</loc>
- <lastmod>2026-04-27T10:18:51+02:00</lastmod>
+ <lastmod>2026-04-30T23:48:14+02:00</lastmod>
</url>
<url>