CVE-2026-103412

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container. This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-09: 210-09
Referenced assets2 URLs
Full discourse2 posts
  • Daily CyberSecurity@Daily_CyberSec

    Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now. #ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412 https://securityonline.info/apache-camel-karavan-vulnerabilities/

    00000337
    13.0K followersView on X
  • VulniPulse@vulnipulse

    CVE advisory: CVE-2026-103412 - apache: Apache Camel Karavan: project file name path traversal when committing a project to Git. https://vulnipulse.com/advisories/apache-cve-2026-103412 #CVE #CyberSecurity #Apache #CamelKaravan

    0000048
    11 followersView on X

Explore more