Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40473

Опубликовано: 27 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.

A flaw was found in the camel-mina component of Apache Camel. This vulnerability allows a remote attacker to achieve arbitrary code execution by sending a specially crafted serialized Java object over the network to the MINA consumer port. The MinaConverter.toObjectInput type converter, used when a Camel route processes network input, fails to apply necessary security filters or class-loading restrictions during object deserialization. This oversight enables an attacker to execute malicious code within the application's context.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4camel-mina-sftpNot affected
Red Hat Fuse 7camel-minaNot affected
Red Hat Fuse 7camel-mina2Not affected
Red Hat Fuse 7camel-mina2-starterNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2463180Apache Camel: camel-mina: Apache Camel camel-mina: Arbitrary code execution via insecure deserialization

EPSS

Процентиль: 55%
0.00872
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.

CVSS3: 8.8
github
4 месяца назад

Camel-MINA Vulnerable to Deserialization of Untrusted Data

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость функции MinaConverter.toObjectInput() компонента camel-mina java-фреймворка Apache Camel, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 55%
0.00872
Низкий

8.8 High

CVSS3