CVE-2026-40048
Apache Software Foundation Apache Camel PQC, Red Hat build of Apache Camel for Spring Boot 4, camel 취약점
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effects in the deserialized object run before the type check. An attacker who can write to the key directory used by a Camel application — for example through a path traversal into the directory, misconfigured filesystem permissions on the v...
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.25% 백분위 16.0% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.27