Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-25747

Apache Camel: unsafe deserialization in the camel-leveldb aggregation repository

Technology

Apache Camel

CVSS Score

8.8 / 10.0

Affected Versions

3.0.0 before 4.10.9; 4.11.0 before 4.14.5; 4.15.0 before 4.18.0

Upstream Fix

4.10.9; 4.14.5; 4.18.0

Published

February 23, 2026

OSSeva Coverage

Fixed upstream

Description

DefaultLevelDBSerializer deserialized data from the LevelDB aggregation repository with no ObjectInputFilter or class restrictions. Anyone able to write to the LevelDB files could inject a serialized object that runs code during normal aggregation. Rated high by the Camel project. Fixed in 4.10.9, 4.14.5 and 4.18.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.0.0 before 4.10.9; 4.11.0 before 4.14.5; 4.15.0 before 4.18.0, you need this patch. Book a discovery call to get covered.