CVE-2026-40047
Apache Software Foundation Apache Camel, camel
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the `CamelDoclingCustomArguments` exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected path values that contained a...
- CVSS
- 9.1
- EPSS
- 1.78% 76.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06