Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-25747
Apache Camel: unsafe deserialization in the camel-leveldb aggregation repository
Technology
Apache Camel
CVSS Score
8.8 / 10.0
Affected Versions
3.0.0 before 4.10.9; 4.11.0 before 4.14.5; 4.15.0 before 4.18.0
Upstream Fix
4.10.9; 4.14.5; 4.18.0
Published
February 23, 2026
OSSeva Coverage
Fixed upstream
Description
DefaultLevelDBSerializer deserialized data from the LevelDB aggregation repository with no ObjectInputFilter or class restrictions. Anyone able to write to the LevelDB files could inject a serialized object that runs code during normal aggregation. Rated high by the Camel project. Fixed in 4.10.9, 4.14.5 and 4.18.0.
Is your Apache Camel deployment affected?
If you're running 3.0.0 before 4.10.9; 4.11.0 before 4.14.5; 4.15.0 before 4.18.0, you need this patch. Book a discovery call to get covered.