Information Exposure Through an Error Message in Apache Camel - CVE-2026-56139

 

Information Exposure Through an Error Message in Apache Camel - CVE-2026-56139

Published: August 24, 2026


Vulnerability identifier: #VU144684
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56139
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to generation of error messages containing sensitive information in the Camel Undertow HTTP server consumer when handling requests that trigger route processing errors. A remote attacker can send a malformed request or invalid parameter to disclose sensitive information.

For Rest DSL consumers, the muteException option was not honored, causing stack traces to be returned even when that option had been enabled.


Affected software

Apache Camel

How to mitigate CVE-2026-56139

Install security update from vendor's website.

Apache Camel - addressed in versions 0.0.0.0, 4.15.0, 4.19.0, 4.21.0

External References

Related Security Bulletins