CVE-2026-40048
Apache Software Foundation Apache Camel PQC, Red Hat build of Apache Camel for Spring Boot 4, camel
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effects in the deserialized object run before the type check. An attacker who can write to the key directory used by a Camel application — for example through a path traversal into the directory, misconfigured filesystem permissions on the v...
- CVSS
- 7.8
- EPSS
- 0.25% 15.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.27