VDB
GHSA-vpr3-2659-rw55
GHSA-vpr3-2659-rw55
PUBLISHED
CVSS 8.800000190734863 HIGH
Camel-MINA Vulnerable to Deserialization of Untrusted Data
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.apache.camel:camel-mina | 3.0.0, 4.15.0, 4.19.0 |
Timeline
- Apr 27, 2026 CVE Published
- May 5, 2026 CVE Updated
- May 6, 2026 Security Advisory
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-40473 advisory
- https://camel.apache.org/security/CVE-2026-40473.html url
- https://github.com/apache/camel package
- https://issues.apache.org/jira/browse/CAMEL-23319 url
- http://www.openwall.com/lists/oss-security/2026/04/26/8 url
- https://github.com/apache/camel/pull/22583 fix
- https://github.com/apache/camel/pull/22584 fix
- https://github.com/apache/camel/pull/22585 fix
- https://github.com/apache/camel/commit/8e7f6335d2b4b096df26f8221723405ceaee275a fix
- https://github.com/apache/camel/commit/b605816d11c253d22989abc290c198be83e3f817 fix
- https://github.com/apache/camel/commit/c35b0a3720f8c80025b06112d5d9c2932426d7f0 fix