Junglewise Threat Intelligence

CVE-2026-40859: Apache Camel RCE via Deserialization in Vertx and Netty HTTP components

CVE-2026-40859 · Severity: high · CVSS 8.1 · Published 2026-07-06

Vendors: Apache.

Executive brief

Apache Camel's HTTP components (Vertx-Http and Netty-Http) contain a critical flaw that allows remote code execution when processing HTTP responses from untrusted backend services. When the transferException option is enabled, the components deserialize Java objects from response bodies without proper validation, potentially allowing attackers to inject malicious code. This affects applications that communicate with compromised or attacker-controlled servers over unencrypted HTTP connections.

Technical details

The vulnerability is a Java deserialization flaw (CWE-502) in the VertxHttpHelper and NettyHttpHelper components. When deserializing HTTP response bodies with Content-Type application/x-java-serialized-object, the code uses a raw java.io.ObjectInputStream without applying an ObjectInputFilter, allowing instantiation of arbitrary classes. The attack path is reachable only when the producer endpoint is configured with transferException=true (or component-level allowJavaSerializedObject=true) and throwExceptionOnFailure is left at its default true value. An attacker who controls the backend HTTP service—either through a man-in-the-middle attack on unencrypted HTTP or by compromising the backend—can return a crafted serialized Java object. If a suitable gadget chain exists on the classpath, this achieves arbitrary remote code execution. Patches in versions 4.14.8, 4.18.3, and 4.20.0 add ObjectInputFilter constraints with an allowlist (java.**, javax.**, org.apache.camel.**, !*) and introduce a new deserializationFilter endpoint option for customization.

Affected products

  • Apache Camel Vertx-Http 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.19.x
  • Apache Camel Netty-Http 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.19.x

Timeline

  • 2026-07-06: disclosed: Vulnerability disclosed in GHSA-6qw3-4796-5984 and CVE-2026-40859
  • 2026-07-06: patched: Patches released: Camel 4.14.8, 4.18.3, and 4.20.0

References

Related threats