CVE-2026-40473
Apache Camel: unsafe deserialization in the camel-mina ObjectInput converter
Technology
Apache Camel
CVSS Score
8.8 / 10.0
Affected Versions
3.0.0 before 4.14.6; 4.15.0 before 4.18.2; 4.19.0 before 4.20.0
Upstream Fix
4.14.6; 4.18.2; 4.20.0
Published
April 27, 2026
OSSeva Coverage
Fixed upstream
Description
MinaConverter.toObjectInput wrapped incoming bytes in an ObjectInputStream with no filter. A route using camel-mina as a TCP or UDP consumer that converts the body to ObjectInput could be made to run code by a crafted serialized object sent to the consumer port. Rated medium by the Camel project. Fixed in 4.14.6, 4.18.2 and 4.20.0.
Is your Apache Camel deployment affected?
If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.2; 4.19.0 before 4.20.0, you need this patch. Book a discovery call to get covered.