CVE-2026-25747
Apache Software Foundation Apache Camel LevelDB, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application. This issue affects Apache Ca...
- CVSS
- 8.8
- EPSS
- 0.90% 56.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.23