Information Exposure Through an Error Message in Apache Camel - CVE-2026-49365

 

Information Exposure Through an Error Message in Apache Camel - CVE-2026-49365

Published: August 24, 2026


Vulnerability identifier: #VU144688
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49365
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive internal information.

The vulnerability exists due to generation of error messages containing sensitive information in the camel-netty-http HTTP server consumer when handling requests that trigger route processing errors. A remote attacker can send a malformed request or invalid parameter to disclose sensitive internal information.

The HTTP response body may include the full Java stack trace, including exception message contents, host and path details, dependency information, and application structure.


Affected software

Apache Camel

How to mitigate CVE-2026-49365

Install security update from vendor's website.

Apache Camel - addressed in versions 0.0.0.0, 4.15.0, 4.19.0, 4.21.0

External References

Related Security Bulletins