GHSA-xw7x-h9fj-p2c7
CRITICALCVE-2026-33701In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. An attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability:
- Affected
- < 2.26.1
- Fixed in
- 2.26.1
- Weakness
- CWE-502
- Published
- 2026-03-25
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference