GHSA-6mcm-j9cj-3vc3 · Severity: medium · Ecosystem: maven — Infinite loop in Apache MINA
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Conclusion & alert: CVE-2021-41973 is rated Moderate Risk (56.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.15%). Core evidence: EPSS rose +1.22% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-08 | 0.93% | 2.15% | +1.22% |
| 2 | 2026-05-27 | 1.81% | 0.93% | -0.88% |
| 3 | 2026-05-02 | — | 1.81% | — |
Full EPSS history (35 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-6mcm-j9cj-3vc3 · Severity: medium · Ecosystem: maven — Infinite loop in Apache MINA
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-41973 unimportant priority: Debian including 2 source packages (mina, mina2), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 6, open 1. | https://security-tracker.debian.org/tracker/CVE-2021-41973 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-41973 |
ubuntu
|
medium | CVE-2021-41973 medium priority: Ubuntu including 2 source packages (mina, mina2), 18 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, questing, upstream, xenial): needs-triage 8, not-affected 6, ignored 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2021-41973 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | mina | < 2.0.22 | cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:* |
| apache | mina | >= 2.1.0, < 2.1.5 | cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:* |
| oracle | banking_payments | 14.5 | cpe:2.3:a:oracle:banking_payments:14.5:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.5 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:* |
| oracle | banking_treasury_management | 14.5 | cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_console | 1.9.0 | cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:* |
| oracle | customer_management_and_segmentation_foundation | 18.0 | cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* |
| oracle | customer_management_and_segmentation_foundation | 19.0 | cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* |
| oracle | flexcube_universal_banking | >= 14.0, <= 14.3 | cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:* |
| oracle | flexcube_universal_banking | 14.5 | cpe:2.3:a:oracle:flexcube_universal_banking:14.5:*:*:*:*:*:*:* |
| oracle | fusion_middleware_common_libraries_and_tools | 12.2.1.3.0 | cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware_common_libraries_and_tools | 12.2.1.4.0 | cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware_common_libraries_and_tools | 14.1.1.0.0 | cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:14.1.1.0.0:*:*:*:*:*:*:* |
| oracle | oss_support_tools | 2.12.42 | cpe:2.3:a:oracle:oss_support_tools:2.12.42:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/11/01/2 | Mailing List Patch Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2021/11/01/8 | Mailing List Third Party Advisory |
| https://lists.apache.org/thread.html/r0b907da9340d5ff4e6c1a4798ef4e79700a668657f27cca8a39e9250%40%3Cdev.mina.apache.org%3E | Mailing List Patch Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |