CVE-2026-40859
Apache Software Foundation Apache Camel, camel
Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream) This deserialization path is reached only when the producer endpoint is configured with transferException=true (or the component-level allowJavaSerializedObject=true) and throwExceptionOnFailure is left at its default value of true; in that case a backend HTTP response with a...
- CVSS
- 8.1
- EPSS
- 0.88% 55.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06