Junglewise Threat Intelligence

CVE-2026-6857: Apache Camel camel-infinispan RCE via Unsafe Deserialization

CVE-2026-6857 · Severity: high · CVSS 7.5 · Published 2026-04-22

Vendors: Apache Software Foundation, Maven, Red Hat, Apache.

Executive brief

Apache Camel's Infinispan component, which is used to integrate data grid storage into integration workflows, is vulnerable to a security flaw. An attacker with low-level access could send specially crafted data to the system, causing it to execute unauthorized commands. This could lead to a complete takeover of the affected server, potentially resulting in data theft or service disruption.

Technical details

A deserialization vulnerability exists in the camel-infinispan component of Apache Camel. The root cause is located in the ProtoStream remote aggregation repository, specifically within DefaultExchangeHolderUtils.deserialize(), which utilizes ClassLoadingAwareObjectInputStream.readObject() without implementing an ObjectInputFilter. A remote attacker with low privileges can exploit this by submitting malicious serialized objects over the network. If successful, this leads to arbitrary code execution (RCE) on the host system. The issue has been addressed in version 4.20.0 by implementing a deserialization filter that defaults to a safe allowlist.

Affected products

  • Apache camel-infinispan < 4.20.0

Timeline

  • 2026-04-21: disclosed: Reported to Red Hat Bugzilla
  • 2026-04-22: advisory: GitHub Advisory published
  • 2026-05-14: patched: Red Hat released security update RHSA-2026:17668

References