Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-27172
Apache Camel: unsafe Java deserialization in the camel-consul ConsulRegistry
Technology
Apache Camel
CVSS Score
8.8 / 10.0
Affected Versions
3.0.0 before 4.14.6; 4.15.0 before 4.18.1
Upstream Fix
4.14.6; 4.18.1; 4.19.0
Published
April 27, 2026
OSSeva Coverage
Fixed upstream
Description
ConsulRegistry read Java-serialized values from the Consul KV store and deserialized them with no ObjectInputFilter. Anyone able to write to that KV store could run code in the Camel process on the next registry lookup. Rated high by the Camel project. Fixed in 4.14.6, 4.18.1 and 4.19.0.
Is your Apache Camel deployment affected?
If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.1, you need this patch. Book a discovery call to get covered.