Junglewise Threat Intelligence

CVE-2026-40473: Apache Camel camel-mina insecure deserialization in MinaConverter

CVE-2026-40473 · Severity: high · CVSS 8.8 · Published 2026-04-27

Vendors: Apache Software Foundation.

Executive brief

Apache Camel is a popular open-source integration framework used to connect different software applications. A security flaw in its 'camel-mina' component allows an attacker to send specially crafted data over the network to a server. If successful, this could allow the attacker to take full control of the application and execute unauthorized commands, potentially leading to data theft or service disruption.

Technical details

The vulnerability exists in the MinaConverter.toObjectInput(IoBuffer) type converter within the camel-mina component. The root cause is the wrapping of an IoBuffer in a java.io.ObjectInputStream without implementing ObjectInputFilter or class-loading restrictions. When a Camel route is configured as a TCP or UDP consumer and requests conversion to ObjectInput (e.g., via getBody(ObjectInput.class)), an attacker can provide a malicious serialized Java object. During the readObject() process, this triggers arbitrary code execution in the context of the Java application. The issue is resolved in versions 4.14.6, 4.18.2, and 4.20.0.

Affected products

  • Apache Software Foundation Camel Mina 3.0.0 to 4.14.5, 4.15.0 to 4.18.1, 4.19.0 to 4.19.9

Timeline

  • 2026-04-26: disclosed: Initial disclosure on oss-security mailing list
  • 2026-04-27: advisory: Official Apache Camel security advisory published
  • 2026-04-27: patched: Fixes released in versions 4.14.6, 4.18.2, and 4.20.0

References