Junglewise Threat Intelligence

CVE-2026-40858: Apache Camel unsafe deserialization in camel-infinispan

CVE-2026-40858 · Severity: high · CVSS 8.8 · Published 2026-04-27

Technologies: Red Hat build of Apache Camel for Quarkus, Red Hat build of Apache Camel for Spring Boot. Vendors: Red Hat, Apache Software Foundation.

Executive brief

Apache Camel is a popular integration framework used to connect different software applications. A security vulnerability in its Infinispan component allows an attacker who can write data to a shared cache to execute malicious code on the server. This could lead to a full system takeover, data theft, or disruption of business operations.

Technical details

The camel-infinispan component's ProtoStream-based remote aggregation repository utilizes java.io.ObjectInputStream to deserialize data from a remote Infinispan cache without implementing an ObjectInputFilter. An attacker with the ability to write to the Infinispan cache can inject a malicious serialized Java object. When the Camel application performs standard repository operations such as 'get' or 'recover', it deserializes this object, leading to arbitrary code execution (RCE) in the application's context. The vulnerability is mitigated in versions 4.14.7, 4.18.2, and 4.20.0 by introducing proper filtering during deserialization.

Affected products

  • Apache Software Foundation Apache Camel 4.0.0 to 4.14.6, 4.15.0 to 4.18.1, 4.19.0 to 4.19.9
  • Red Hat Red Hat Build of Apache Camel for Quarkus 3.33
  • Red Hat Red Hat build of Apache Camel for Spring Boot 4.18.1

Timeline

  • 2026-04-27: advisory: Initial advisory published by Apache and NVD
  • 2026-05-14: patched: Red Hat released security updates for Camel Spring Boot and Quarkus variants

References

Related threats