CVE-2026-40473Disclosure(apache / camel)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
camel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-10: 1Exploit Tool / Code · 2026-07-10: 1Technical Details · 2026-04-27: 2Technical Details · 2026-07-10: 104-2604-2707-10
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Exploit
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-272
Disclosure2
2026-07-101
Exploit1
Full discourse4 posts
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-40473 PT ID: PT-2026-35371 Vendor: Apache Software Foundation Product: Apache Camel Mina Description: The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a http://java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35371 • https://github.com/oscerd/CVE-2026-40473 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑40473 has been published, detailing an arbitrary code execution vulnerability in Apache Camel Mina and providing executable code via a public GitHub repository.

    010982.9K
    3.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40473 The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a http://java.io.ObjectInputStream without applying any ObjectInputFilte… https://www.cve.org/CVERecord?id=CVE-2026-40473 ----- Traducción: CV… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑40473, describing how the camel‑mina component’s converter mishandles ObjectInputStream, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000033
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40473 The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a http://java.io.ObjectInputStream without applying any ObjectInputFilte… https://www.cve.org/CVERecord?id=CVE-2026-40473

    Post summary

    The excerpt summarizes a vulnerability in camel-mina's MinaConverter that improperly wraps IoBuffers in an ObjectInputStream without filtering, indicating a potential remote code execution risk.

    00000118
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40473 CVE-2026-40473 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40473

    Post summary

    The post simply references CVE-2026-40473 with a link, providing no additional information about exploitation, patches, or technical details.

    0000047
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.19.0--

Explore more