CVE-2026-25747
Apache Software Foundation Apache Camel LevelDB, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7 취약점
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application. This issue affects Apache Ca...
- 대응 우선순위
- 점검
- CVSS
- 8.8
- EPSS
- 0.90% 백분위 56.3% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.02.23