logo

Apache Camel Under Fire: Multiple RCE Flaws Expose Critical Integration Infrastructure

ID: 4ce8b4b4-db53-5be7-8365-c383feb02755

STIX ID: report--4ce8b4b4-db53-5be7-8365-c383feb02755

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Researchers disclosed multiple critical vulnerabilities in the Apache Camel integration framework that allow unauthenticated or remotely triggered Remote Code Execution through unsafe Java deserialization and header/query-parameter injection across components (Consul, Infinispan, camel-coap, camel-mail, and key lifecycle handling). Several CVEs are noted, including cases where attackers who can write to backing stores or send a single CoAP packet can trigger gadget chains or inject Camel-prefixed headers to execute OS commands; fixes and recommended upgrade versions are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.