CVE-2026-25747Disclosure(apache / camel)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache camel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.5, from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue. For the 4.10.x LTS releases, users are recommended to upgrade to 4.10.9, while for 4.14.x LTS releases, users are recommended to upgrade to 4.14.5

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-1902-2502-2702-28
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure1Patch1
2026-02-251
Disclosure1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25747: Apache Camel: Deserialization of Untrusted Data in Camel LevelDB https://www.openwall.com/lists/oss-security/2026/02/18/6 CVE-2026-23552: Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy https://www.openwall.com/lists/oss-security/2026/02/18/7

    Post summary

    Two new CVE disclosures for Apache Camel components were announced, highlighting deserialization and cross‑realm token bypass vulnerabilities.

    00042454
    4.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25747 (CVSS:8.8, HIGH) is Modified. Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSeri..https://nvd.nist.gov/vuln/detail/CVE-2026-25747 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-25747, a high‐severity deserialization flaw in Apache Camel's LevelDB component, providing its CVSS score and brief description.

    0000031
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25747 (CVSS:8.8, HIGH) is Modified. Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSeri..https://nvd.nist.gov/vuln/detail/CVE-2026-25747 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-25747, a high‑severity deserialization vulnerability in Apache Camel LevelDB, providing CVSS score and component details, but offers no PoC, exploit, patch, or active exploitation information.

    0000026
    173 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [HIGH] CVE-2026-25747 in Apache Camel-LevelDB Deserialization flaw in Apache Camel-LevelDB component. CVE: CVE-2026-25747 • APT: N/A • Status: ACTIVE Affects data serialization processes. #mysocAi #CyberSecurityusin… https://www.thehackerwire.com/vulnerability/CVE-2026-25747/

    Post summary

    The post announces a deserialization vulnerability (CVE‑2026‑25747) in Apache Camel‑LevelDB, noting its active status but providing no PoC, exploit, patch, or evidence of exploitation.

    000008
    3 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache Camel patches critical flaws in Keycloak (CVE-2026-23552) and LevelDB (CVE-2026-25747) components that allow auth bypass and RCE. Update to 4.18.0. #ApacheCamel #CyberSecurity #CVE #InfoSec #Keycloak #JavaSecurity #DevSecOps https://securityonline.info/apache-camel-patches-critical-keycloak-leveldb-flaws/

    Post summary

    Apache Camel has released patch 4.18.0 to fix critical authentication bypass and remote code execution flaws in Keycloak and LevelDB components.

    00000171
    10.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more