Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-66908

Apache Camel: platform-http-main JWT authentication skips issuer and audience checks

Technology

Apache Camel

CVSS Score

7.5 / 10.0

Affected Versions

4.8.0 before 4.22.0

Upstream Fix

4.22.0

Published

August 24, 2026

OSSeva Coverage

Fixed upstream

Description

When JWT authentication on the camel-main embedded HTTP server was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted. Rated high by the Camel project. Fixed in 4.22.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 4.8.0 before 4.22.0, you need this patch. Book a discovery call to get covered.