Junglewise Threat Intelligence

CVE-2026-40047: Apache Camel argument injection in Docling component

CVE-2026-40047 · Severity: critical · CVSS 9.1 · Published 2026-07-06

Technologies: Apache Camel. Vendors: Maven, Apache.

Executive brief

Apache Camel's Docling component is used to integrate document conversion workflows into message routing applications. The component invokes an external docling command-line tool, but failed to properly validate custom arguments supplied through message headers, allowing an attacker who can control message content to inject arbitrary CLI flags and access files outside intended directories. This could lead to unauthorized data access or manipulation of the conversion process.

Technical details

The vulnerability is an argument injection (CWE-88) combined with path traversal in the DoclingProducer class. Custom CLI arguments from the CamelDoclingCustomArguments exchange header (a List<String>) are appended to the ProcessBuilder argument list with insufficient validation: the original code used only a denylist approach and checked for literal "../" sequences in path values. An attacker controlling external message content routed into these exchange headers can bypass the weak path traversal check (e.g., using "..\" or other normalization tricks) and inject unrecognized docling CLI flags. Because Camel builds the invocation using ProcessBuilder's list-based form, shell metacharacter injection is not possible, but the argument injection and path traversal remain exploitable. The fix (in CAMEL-23212, included in 4.18.3 and 4.19.0+) switches to an allowlist of recognized flags, normalizes paths with Path.normalize() before validation, and defensively rejects shell metacharacters.

Affected products

  • Apache Camel 4.15.0 through 4.18.2

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: patched: Fix included in Apache Camel 4.18.3 and 4.19.0+

References

Related threats