CVE-2026-40473
Apache Software Foundation Apache Camel Mina, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject(). This issue affects Apache Camel: from 3.0.0...
- CVSS
- 8.8
- EPSS
- 0.87% 55.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.27