CVE-2026-40048General(apache / camel)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effects in the deserialized object run before the type check. An attacker who can write to the key directory used by a Camel application — for example through a path traversal into the directory, misconfigured filesystem permissions on the volume where keys are stored, a compromised key provisioning pipeline, or a symlink attack — can place a crafted serialized Java object that, when deserialized during normal key lifecycle operations, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.19.0 before 4.20.0, from 4.18.0 before 4.18.2. Users are recommended to upgrade to version 4.20.0, which fixes the issue by replacing java.io.ObjectInputStream-based key and metadata storage with standard PKCS#8 (private key) / X.509 SubjectPublicKeyInfo (public key) Base64 JSON encoding. For users on the 4.18.x LTS releases stream, upgrade to 4.18.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-27); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
camel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-10: 2Exploit Tool / Code · 2026-07-10: 2Patch / Workaround · 2026-07-10: 1Technical Details · 2026-04-27: 1Technical Details · 2026-07-10: 204-2604-2707-10
Signal classification4 categories
General
240.0%
Disclosure
120.0%
Exploit
120.0%
PoC
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-272
Disclosure1General1
2026-07-102
Exploit1PoC1
Full discourse5 posts
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-40048 PT ID: PT-2026-35369 Vendor: Apache Software Foundation Product: Apache Camel PQC Description: The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of <keyId>.key files in the configured key directory using http://java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to http://java.security.KeyPair is evaluated only after readObject() has already returned, so any readObject() side effects in the deserialized object run before the type check. An attacker who can write to the key directory used by a Camel application — for example through a path traversal into the directory, misconfigured filesystem permissions on the volume where keys are stored, a compromised key provisioning pipeline, or a symlink attack — can place a crafted serialized Java object that, when deserialized during normal key lifecycle operations, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.19.0 before 4.20.0, from 4.18.0 before 4.18.2. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35369 • https://github.com/oscerd/CVE-2026-40048 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑40048 is publicly available, outlining deserialization‑based arbitrary code execution in Apache Camel PQC, yet there is no evidence of current active exploitation or patch information.

    00024858
    3.4K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-40048: A PoC has been released for an Apache Camel PQC vulnerability that could lead to remote code execution (RCE) through unsafe Java deserialization. Affected versions should be upgraded immediately. 🔗 https://github.com/oscerd/CVE-2026-40048 #CyberSecurity #CVE #Apache #Camel

    Post summary

    A proof‑of‑concept demonstrating remote code execution via unsafe Java deserialization has been released for CVE‑2026‑40048; affected Apache Camel users are encouraged to upgrade immediately.

    0001075
    69 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40048 The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `

    Post summary

    The text provides a brief, incomplete mention of CVE-2026-40048 but lacks substantive details or actionable information.

    0000032
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40048 The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `&lt;keyId&gt;.key` files in the configured key directory using http://java.io.ObjectInputStream with… https://www.cve.org/CVERecord?id=CVE-2026-40048

    Post summary

    The post announces CVE-2026-40048, detailing a deserialization vulnerability in Apache Camel-PQC's FileBasedKeyLifecycleManager that processes key files with ObjectInputStream.

    00000119
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40048 CVE-2026-40048 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40048

    Post summary

    The post merely repeats the CVE identifier and includes a generic link, providing no substantive details about exploitation or mitigation.

    0000048
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.19.0--

Explore more