Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-40473

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-40473
  • Apache » Camel » Version: 3.0.0
    cpe:2.3:a:apache:camel:3.0.0
  • Apache » Camel » Version: 3.0.1
    cpe:2.3:a:apache:camel:3.0.1
  • Apache » Camel » Version: 3.1.0
    cpe:2.3:a:apache:camel:3.1.0
  • Apache » Camel » Version: 3.10.0
    cpe:2.3:a:apache:camel:3.10.0
  • Apache » Camel » Version: 3.11.0
    cpe:2.3:a:apache:camel:3.11.0
  • Apache » Camel » Version: 3.11.1
    cpe:2.3:a:apache:camel:3.11.1
  • Apache » Camel » Version: 3.11.2
    cpe:2.3:a:apache:camel:3.11.2
  • Apache » Camel » Version: 3.11.3
    cpe:2.3:a:apache:camel:3.11.3
  • Apache » Camel » Version: 3.11.4
    cpe:2.3:a:apache:camel:3.11.4
  • Apache » Camel » Version: 3.11.5
    cpe:2.3:a:apache:camel:3.11.5
  • Apache » Camel » Version: 3.11.6
    cpe:2.3:a:apache:camel:3.11.6
  • Apache » Camel » Version: 3.11.7
    cpe:2.3:a:apache:camel:3.11.7
  • Apache » Camel » Version: 3.12.0
    cpe:2.3:a:apache:camel:3.12.0
  • Apache » Camel » Version: 3.13.0
    cpe:2.3:a:apache:camel:3.13.0
  • Apache » Camel » Version: 3.14.0
    cpe:2.3:a:apache:camel:3.14.0
  • Apache » Camel » Version: 3.14.1
    cpe:2.3:a:apache:camel:3.14.1
  • Apache » Camel » Version: 3.14.2
    cpe:2.3:a:apache:camel:3.14.2
  • Apache » Camel » Version: 3.14.3
    cpe:2.3:a:apache:camel:3.14.3
  • Apache » Camel » Version: 3.14.4
    cpe:2.3:a:apache:camel:3.14.4
  • Apache » Camel » Version: 3.14.5
    cpe:2.3:a:apache:camel:3.14.5
  • Apache » Camel » Version: 3.14.6
    cpe:2.3:a:apache:camel:3.14.6
  • Apache » Camel » Version: 3.14.7
    cpe:2.3:a:apache:camel:3.14.7
  • Apache » Camel » Version: 3.14.8
    cpe:2.3:a:apache:camel:3.14.8
  • Apache » Camel » Version: 3.14.9
    cpe:2.3:a:apache:camel:3.14.9
  • Apache » Camel » Version: 3.15.0
    cpe:2.3:a:apache:camel:3.15.0
  • Apache » Camel » Version: 3.16.0
    cpe:2.3:a:apache:camel:3.16.0
  • Apache » Camel » Version: 3.17.0
    cpe:2.3:a:apache:camel:3.17.0
  • Apache » Camel » Version: 3.18.0
    cpe:2.3:a:apache:camel:3.18.0
  • Apache » Camel » Version: 3.18.1
    cpe:2.3:a:apache:camel:3.18.1
  • Apache » Camel » Version: 3.18.2
    cpe:2.3:a:apache:camel:3.18.2
  • Apache » Camel » Version: 3.18.3
    cpe:2.3:a:apache:camel:3.18.3
  • Apache » Camel » Version: 3.18.4
    cpe:2.3:a:apache:camel:3.18.4
  • Apache » Camel » Version: 3.18.7
    cpe:2.3:a:apache:camel:3.18.7
  • Apache » Camel » Version: 3.18.8
    cpe:2.3:a:apache:camel:3.18.8
  • Apache » Camel » Version: 3.19.0
    cpe:2.3:a:apache:camel:3.19.0
  • Apache » Camel » Version: 3.2.0
    cpe:2.3:a:apache:camel:3.2.0
  • Apache » Camel » Version: 3.20.0
    cpe:2.3:a:apache:camel:3.20.0
  • Apache » Camel » Version: 3.20.1
    cpe:2.3:a:apache:camel:3.20.1
  • Apache » Camel » Version: 3.20.2
    cpe:2.3:a:apache:camel:3.20.2
  • Apache » Camel » Version: 3.20.3
    cpe:2.3:a:apache:camel:3.20.3
  • Apache » Camel » Version: 3.20.4
    cpe:2.3:a:apache:camel:3.20.4
  • Apache » Camel » Version: 3.20.5
    cpe:2.3:a:apache:camel:3.20.5
  • Apache » Camel » Version: 3.20.6
    cpe:2.3:a:apache:camel:3.20.6
  • Apache » Camel » Version: 3.20.7
    cpe:2.3:a:apache:camel:3.20.7
  • Apache » Camel » Version: 3.20.8
    cpe:2.3:a:apache:camel:3.20.8
  • Apache » Camel » Version: 3.20.9
    cpe:2.3:a:apache:camel:3.20.9
  • Apache » Camel » Version: 3.21.0
    cpe:2.3:a:apache:camel:3.21.0
  • Apache » Camel » Version: 3.21.1
    cpe:2.3:a:apache:camel:3.21.1
  • Apache » Camel » Version: 3.21.2
    cpe:2.3:a:apache:camel:3.21.2
  • Apache » Camel » Version: 3.21.3
    cpe:2.3:a:apache:camel:3.21.3
  • Apache » Camel » Version: 3.21.4
    cpe:2.3:a:apache:camel:3.21.4
  • Apache » Camel » Version: 3.21.5
    cpe:2.3:a:apache:camel:3.21.5
  • Apache » Camel » Version: 3.22.0
    cpe:2.3:a:apache:camel:3.22.0
  • Apache » Camel » Version: 3.22.1
    cpe:2.3:a:apache:camel:3.22.1
  • Apache » Camel » Version: 3.22.2
    cpe:2.3:a:apache:camel:3.22.2
  • Apache » Camel » Version: 3.22.3
    cpe:2.3:a:apache:camel:3.22.3
  • Apache » Camel » Version: 3.22.4
    cpe:2.3:a:apache:camel:3.22.4
  • Apache » Camel » Version: 3.3.0
    cpe:2.3:a:apache:camel:3.3.0
  • Apache » Camel » Version: 3.4.0
    cpe:2.3:a:apache:camel:3.4.0
  • Apache » Camel » Version: 3.4.1
    cpe:2.3:a:apache:camel:3.4.1
  • Apache » Camel » Version: 3.4.2
    cpe:2.3:a:apache:camel:3.4.2
  • Apache » Camel » Version: 3.4.3
    cpe:2.3:a:apache:camel:3.4.3
  • Apache » Camel » Version: 3.4.4
    cpe:2.3:a:apache:camel:3.4.4
  • Apache » Camel » Version: 3.4.5
    cpe:2.3:a:apache:camel:3.4.5
  • Apache » Camel » Version: 3.4.6
    cpe:2.3:a:apache:camel:3.4.6
  • Apache » Camel » Version: 3.5.0
    cpe:2.3:a:apache:camel:3.5.0
  • Apache » Camel » Version: 3.6.0
    cpe:2.3:a:apache:camel:3.6.0
  • Apache » Camel » Version: 3.7.0
    cpe:2.3:a:apache:camel:3.7.0
  • Apache » Camel » Version: 3.7.1
    cpe:2.3:a:apache:camel:3.7.1
  • Apache » Camel » Version: 3.7.2
    cpe:2.3:a:apache:camel:3.7.2
  • Apache » Camel » Version: 3.7.3
    cpe:2.3:a:apache:camel:3.7.3
  • Apache » Camel » Version: 3.7.4
    cpe:2.3:a:apache:camel:3.7.4
  • Apache » Camel » Version: 3.7.5
    cpe:2.3:a:apache:camel:3.7.5
  • Apache » Camel » Version: 3.7.6
    cpe:2.3:a:apache:camel:3.7.6
  • Apache » Camel » Version: 3.7.7
    cpe:2.3:a:apache:camel:3.7.7
  • Apache » Camel » Version: 3.8.0
    cpe:2.3:a:apache:camel:3.8.0
  • Apache » Camel » Version: 3.9.0
    cpe:2.3:a:apache:camel:3.9.0
  • Apache » Camel » Version: 4.0.0
    cpe:2.3:a:apache:camel:4.0.0
  • Apache » Camel » Version: 4.0.4
    cpe:2.3:a:apache:camel:4.0.4
  • Apache » Camel » Version: 4.0.5
    cpe:2.3:a:apache:camel:4.0.5
  • Apache » Camel » Version: 4.0.6
    cpe:2.3:a:apache:camel:4.0.6
  • Apache » Camel » Version: 4.1.0
    cpe:2.3:a:apache:camel:4.1.0
  • Apache » Camel » Version: 4.10.0
    cpe:2.3:a:apache:camel:4.10.0
  • Apache » Camel » Version: 4.10.1
    cpe:2.3:a:apache:camel:4.10.1
  • Apache » Camel » Version: 4.10.2
    cpe:2.3:a:apache:camel:4.10.2
  • Apache » Camel » Version: 4.10.3
    cpe:2.3:a:apache:camel:4.10.3
  • Apache » Camel » Version: 4.10.4
    cpe:2.3:a:apache:camel:4.10.4
  • Apache » Camel » Version: 4.10.5
    cpe:2.3:a:apache:camel:4.10.5
  • Apache » Camel » Version: 4.10.6
    cpe:2.3:a:apache:camel:4.10.6
  • Apache » Camel » Version: 4.10.7
    cpe:2.3:a:apache:camel:4.10.7
  • Apache » Camel » Version: 4.10.8
    cpe:2.3:a:apache:camel:4.10.8
  • Apache » Camel » Version: 4.10.9
    cpe:2.3:a:apache:camel:4.10.9
  • Apache » Camel » Version: 4.11.0
    cpe:2.3:a:apache:camel:4.11.0
  • Apache » Camel » Version: 4.12.0
    cpe:2.3:a:apache:camel:4.12.0
  • Apache » Camel » Version: 4.13.0
    cpe:2.3:a:apache:camel:4.13.0
  • Apache » Camel » Version: 4.14.0
    cpe:2.3:a:apache:camel:4.14.0
  • Apache » Camel » Version: 4.14.1
    cpe:2.3:a:apache:camel:4.14.1
  • Apache » Camel » Version: 4.14.2
    cpe:2.3:a:apache:camel:4.14.2
  • Apache » Camel » Version: 4.14.3
    cpe:2.3:a:apache:camel:4.14.3
  • Apache » Camel » Version: 4.14.4
    cpe:2.3:a:apache:camel:4.14.4
  • Apache » Camel » Version: 4.14.5
    cpe:2.3:a:apache:camel:4.14.5
  • Apache » Camel » Version: 4.15.0
    cpe:2.3:a:apache:camel:4.15.0
  • Apache » Camel » Version: 4.16.0
    cpe:2.3:a:apache:camel:4.16.0
  • Apache » Camel » Version: 4.17.0
    cpe:2.3:a:apache:camel:4.17.0
  • Apache » Camel » Version: 4.17.0.1
    cpe:2.3:a:apache:camel:4.17.0.1
  • Apache » Camel » Version: 4.18.0
    cpe:2.3:a:apache:camel:4.18.0
  • Apache » Camel » Version: 4.19.0
    cpe:2.3:a:apache:camel:4.19.0
  • Apache » Camel » Version: 4.2.0
    cpe:2.3:a:apache:camel:4.2.0
  • Apache » Camel » Version: 4.3.0
    cpe:2.3:a:apache:camel:4.3.0
  • Apache » Camel » Version: 4.4.0
    cpe:2.3:a:apache:camel:4.4.0
  • Apache » Camel » Version: 4.4.1
    cpe:2.3:a:apache:camel:4.4.1
  • Apache » Camel » Version: 4.4.2
    cpe:2.3:a:apache:camel:4.4.2
  • Apache » Camel » Version: 4.4.3
    cpe:2.3:a:apache:camel:4.4.3
  • Apache » Camel » Version: 4.4.4
    cpe:2.3:a:apache:camel:4.4.4
  • Apache » Camel » Version: 4.4.5
    cpe:2.3:a:apache:camel:4.4.5
  • Apache » Camel » Version: 4.5.0
    cpe:2.3:a:apache:camel:4.5.0
  • Apache » Camel » Version: 4.6.0
    cpe:2.3:a:apache:camel:4.6.0
  • Apache » Camel » Version: 4.7.0
    cpe:2.3:a:apache:camel:4.7.0
  • Apache » Camel » Version: 4.8.0
    cpe:2.3:a:apache:camel:4.8.0
  • Apache » Camel » Version: 4.8.1
    cpe:2.3:a:apache:camel:4.8.1
  • Apache » Camel » Version: 4.8.2
    cpe:2.3:a:apache:camel:4.8.2
  • Apache » Camel » Version: 4.8.3
    cpe:2.3:a:apache:camel:4.8.3
  • Apache » Camel » Version: 4.8.4
    cpe:2.3:a:apache:camel:4.8.4
  • Apache » Camel » Version: 4.8.5
    cpe:2.3:a:apache:camel:4.8.5
  • Apache » Camel » Version: 4.8.6
    cpe:2.3:a:apache:camel:4.8.6
  • Apache » Camel » Version: 4.8.7
    cpe:2.3:a:apache:camel:4.8.7
  • Apache » Camel » Version: 4.8.8
    cpe:2.3:a:apache:camel:4.8.8
  • Apache » Camel » Version: 4.8.9
    cpe:2.3:a:apache:camel:4.8.9
  • Apache » Camel » Version: 4.9.0
    cpe:2.3:a:apache:camel:4.9.0


Contact Us

Shodan ® - All rights reserved