CVE-2026-47321 PUBLISHED

Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate

Assigner: apache
Reserved: 19.05.2026 Published: 21.09.2026 Updated: 21.09.2026

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.

Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.

The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)

For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:

public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.

Here are the additional constructor:

public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,

<pre> final int compressionLevel, final int maxDecompressedSize, final long maxDecompressRatio, final long decompressRatioMinSize) </pre>

Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:

CompressionFilter compressionFilter = new CompressionFilter()

.setCompressionLevel(Zlib.COMPRESSION_MAX)

.setMaxDecompressedSize(1_000_000)

.setMaxDecompressRatio(100).

.setDecompressRatioMinSize(100_000); 

Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Apache Software Foundation
Product Apache MINA
Versions Default: unaffected
  • affected from 2.2.0 to 2.2.8 (excl.)
  • affected from 2.1.0 to 2.1.13 (excl.)
  • affected from 2.0.0 to 2.0.29 (excl.)

Credits

  • Venkatraman Kumar, SecurIn finder

References

Problem Types

  • CWE-409: Improper Handling of Highly Compressed Data — Data Amplification CWE
  • CWE-789: Memory Allocation with Excessive Size Value CWE