Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-40473

Apache Camel: unsafe deserialization in the camel-mina ObjectInput converter

Technology

Apache Camel

CVSS Score

8.8 / 10.0

Affected Versions

3.0.0 before 4.14.6; 4.15.0 before 4.18.2; 4.19.0 before 4.20.0

Upstream Fix

4.14.6; 4.18.2; 4.20.0

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

MinaConverter.toObjectInput wrapped incoming bytes in an ObjectInputStream with no filter. A route using camel-mina as a TCP or UDP consumer that converts the body to ObjectInput could be made to run code by a crafted serialized object sent to the consumer port. Rated medium by the Camel project. Fixed in 4.14.6, 4.18.2 and 4.20.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.2; 4.19.0 before 4.20.0, you need this patch. Book a discovery call to get covered.