CVE-2026-27172
- EPSS 0.17%
- Veröffentlicht 27.04.2026 09:59:45
- Zuletzt bearbeitet 28.04.2026 19:40:52
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.r...
- EPSS 0.46%
- Veröffentlicht 27.04.2026 09:58:48
- Zuletzt bearbeitet 28.04.2026 19:39:35
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution ...
CVE-2026-33454
- EPSS 0.22%
- Veröffentlicht 27.04.2026 09:42:39
- Zuletzt bearbeitet 28.04.2026 19:42:14
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the ...
CVE-2026-40022
- EPSS 0.16%
- Veröffentlicht 27.04.2026 09:40:28
- Zuletzt bearbeitet 28.04.2026 19:41:41
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the Basi...
CVE-2026-40858
- EPSS 0.17%
- Veröffentlicht 27.04.2026 09:38:55
- Zuletzt bearbeitet 28.04.2026 19:41:18
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan...
CVE-2026-40453
- EPSS 0.19%
- Veröffentlicht 27.04.2026 08:23:20
- Zuletzt bearbeitet 28.04.2026 19:43:55
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not a...
CVE-2026-40860
- EPSS 0.66%
- Veröffentlicht 27.04.2026 08:03:19
- Zuletzt bearbeitet 28.04.2026 19:42:46
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allow...
CVE-2026-40048
- EPSS 0.07%
- Veröffentlicht 27.04.2026 07:53:54
- Zuletzt bearbeitet 28.04.2026 19:43:29
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java....
CVE-2026-40473
- EPSS 0.12%
- Veröffentlicht 27.04.2026 07:51:59
- Zuletzt bearbeitet 28.04.2026 19:43:05
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP ...
CVE-2026-25747
- EPSS 0.06%
- Veröffentlicht 23.02.2026 08:45:45
- Zuletzt bearbeitet 26.02.2026 22:20:46
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any O...