CVE-2026-43866
Apache Camel: JMS deserialization filter bypass through DefaultExchangeHolder
Technology
Apache Camel
CVSS Score
7.3 / 10.0
Affected Versions
3.0.0 before 4.14.8; 4.15.0 before 4.18.3; 4.19.0 before 4.21.0
Upstream Fix
4.14.8; 4.18.3; 4.21.0
Published
July 6, 2026
OSSeva Coverage
Fixed upstream
Description
The class check added for CVE-2026-40860 allows the org.apache.camel namespace, and DefaultExchangeHolder lives there. A JMS ObjectMessage carrying a forged DefaultExchangeHolder passed the check and was unmarshalled into the exchange, letting anyone able to publish to the queue set the body, headers, properties, variables and exception. Rated high by the Camel project. Fixed in 4.14.8, 4.18.3 and 4.21.0.
Is your Apache Camel deployment affected?
If you're running 3.0.0 before 4.14.8; 4.15.0 before 4.18.3; 4.19.0 before 4.21.0, you need this patch. Book a discovery call to get covered.