Executive brief
Apache Camel's Keycloak authentication helper fails to validate whether access tokens have expired or not yet become valid, accepting tokens outside their intended lifetime. This allows attackers to reuse expired tokens to gain unauthorized access to Camel routes that rely on this helper for authentication, potentially leading to data breach, unauthorized operations, or service compromise.
Technical details
The KeycloakSecurityHelper.parseAndVerifyAccessToken method builds a Keycloak TokenVerifier using only subject-exists and realm-URL checks, but does not call withDefaultChecks(), which means the built-in IS_ACTIVE predicate (which validates exp and nbf claims) is never applied. This is a logic error in how the TokenVerifier is configured: withChecks() appends to an empty check list rather than augmenting the defaults. As a result, the helper verifies token signature, subject, and issuer but skips expiration and not-before validation. An attacker can obtain a valid token, wait for it to expire, and reuse it to authenticate to unpatched Camel routes. Network-reachable routes that depend on this helper accept the expired token without any additional privileges or user interaction required. Fix: upgrade to version 4.21.0 (or 4.18.3 for the 4.18.x stream) to include the IS_ACTIVE check in token validation.
Affected products
- Apache Camel 4.18.0 to 4.18.2, 4.19.0 to 4.20.x
Timeline
- 2026-07-06: disclosed
- 2026-07-06: patched: versions 4.18.3 and 4.21.0 released