Deserialization of Untrusted Data in Apache Camel - CVE-2026-40858
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unsafe deserialization in the ProtoStream-based remote aggregation repository of the camel-infinispan component when deserializing data read from a remote Infinispan cache during aggregation repository operations. A remote user can write a crafted serialized Java object to the cache to execute arbitrary code.
Exploitation requires the ability to write to the Infinispan cache used by the application.