CVE-2026-27172
Apache Software Foundation Apache Camel, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilter. An attacker who can write to the Consul KV store backing a Camel ConsulRegistry instance could inject a malicious serialized Java object that is deserialized the next time Camel performs a lookup against that registry, leading to arbitrary code execution in the Camel process. The issue mirror...
- CVSS
- 8.8
- EPSS
- 0.67% 48.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.27