Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-27172

Apache Camel: unsafe Java deserialization in the camel-consul ConsulRegistry

Technology

Apache Camel

CVSS Score

8.8 / 10.0

Affected Versions

3.0.0 before 4.14.6; 4.15.0 before 4.18.1

Upstream Fix

4.14.6; 4.18.1; 4.19.0

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

ConsulRegistry read Java-serialized values from the Consul KV store and deserialized them with no ObjectInputFilter. Anyone able to write to that KV store could run code in the Camel process on the next registry lookup. Rated high by the Camel project. Fixed in 4.14.6, 4.18.1 and 4.19.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.1, you need this patch. Book a discovery call to get covered.