Apache Camel camel-pqc Unsafe Java Deserialization Vulnerability: Upgrade Required for Key Management Security
ID: 53691b3f-1e09-5a00-aed5-75aa2bd9961b
STIX ID: report--53691b3f-1e09-5a00-aed5-75aa2bd9961b
Feed Name: Arctic Wolf Blog
**Executive Summary:** Apache disclosed CVE-2026-43867, a high-severity (CVSS 9.8) deserialization vulnerability in Apache Camel's camel-pqc AwsSecretsManagerKeyLifecycleManager that can lead to remote code execution if an attacker can write key-metadata secrets in AWS Secrets Manager; fixes are available in Apache Camel 4.18.3 and 4.21.0, a public proof-of-concept exists, and recommended actions include upgrading, restricting IAM PutSecretValue access, enabling JVM serialization filters, monitoring CloudTrail, and removing gadget-prone libraries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
