Junglewise Threat Intelligence

CVE-2026-56139: Apache Camel Undertow information disclosure in error messages

CVE-2026-56139 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Apache Camel. Vendors: Apache Software Foundation, Apache.

Executive brief

Apache Camel's Undertow HTTP server component exposes detailed Java error stack traces to clients when processing errors occur, by default. An attacker can send malformed requests to trigger errors and receive sensitive information including hardcoded credentials, internal hostnames, filesystem paths, database names, and application architecture details. This information can be used to plan further attacks against the system.

Technical details

This is a generation of error message containing sensitive information vulnerability (CWE-209) in the camel-undertow component. The muteException consumer option, which controls whether detailed exception stack traces are returned to clients, defaulted to false in camel-undertow, contrary to behavior in other Camel HTTP components (camel-http, camel-jetty, camel-servlet, camel-platform-http) which default it to true. With muteException=false, any unauthenticated network client reaching the endpoint can send requests (e.g., malformed body, invalid parameters) to trigger route processing exceptions and receive the full Java stack trace in the HTTP response body. Additionally, for Rest DSL consumers, the muteException option was ignored entirely due to a hard-coded false value in RestUndertowHttpBinding, causing stack traces to be returned even when muteException=true was explicitly configured. Stack traces can leak credentials, internal hostnames, IP addresses, filesystem paths, dependency versions, database names, and structural details of the application.

Affected products

  • Apache Camel 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.x

Timeline

  • 2026-07-06: disclosed: Vulnerability published as CVE-2026-56139 and GHSA-hjg2-f45w-c566
  • 2026-07-06: patched: Fixed in Camel 4.21.0, 4.18.3, and 4.14.8

References