Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-43866

Apache Camel: JMS deserialization filter bypass through DefaultExchangeHolder

Technology

Apache Camel

CVSS Score

7.3 / 10.0

Affected Versions

3.0.0 before 4.14.8; 4.15.0 before 4.18.3; 4.19.0 before 4.21.0

Upstream Fix

4.14.8; 4.18.3; 4.21.0

Published

July 6, 2026

OSSeva Coverage

Fixed upstream

Description

The class check added for CVE-2026-40860 allows the org.apache.camel namespace, and DefaultExchangeHolder lives there. A JMS ObjectMessage carrying a forged DefaultExchangeHolder passed the check and was unmarshalled into the exchange, letting anyone able to publish to the queue set the body, headers, properties, variables and exception. Rated high by the Camel project. Fixed in 4.14.8, 4.18.3 and 4.21.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.0.0 before 4.14.8; 4.15.0 before 4.18.3; 4.19.0 before 4.21.0, you need this patch. Book a discovery call to get covered.