Skip to content
VulniPulse
High8.1Red Hat Linux

High [CVE-2026-40859] Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data

This high-severity Red Hat Linux advisory covers CVE-2026-40859 affecting Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16, Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat build of Apache Camel 4 for Quarkus 3.

CVE-2026-40859 Published Jul 6, 2026Updated by vendor Jul 6, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Deserialization of Untrusted Data vulnerability in Apache Camel.

The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream) This deserialization path is reached only when the producer endpoint is configured with transferException=true (or the component-level allowJavaSerializedObject=true) and throwExceptionOnFailure is left at its default value of true; in that case a backend HTTP response with a 5xx status and the application/x-java-serialized-object content type has its body deserialized with no class restrictions.

An attacker who controls the backend the Camel producer talks to - through a man-in-the-middle position on an unencrypted (plain HTTP) connection, or by compromising the backend service - can return a crafted serialized Java object and, if a suitable gadget chain is present on the classpath, achieve remote code execution on the Camel application host.

The path is not reachable in the default configuration, where transferException is false. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.20.0.

Users are recommended to upgrade to version 4.20.0, which fixes the issue.

Affected versions
  • < 4.0.0
  • < 4.14.8
  • < 4.15.0
  • < 4.18.3
  • < 4.19.0
  • < 4.20.0

Official advisory · high-confidence parse· fetched 6 hours ago·verify at source

Fixed versions
  • 4.20.0
  • 4.14
  • 4.14.8
  • 4.18
  • 4.18.3
  • camel-vertx-http
  • RHSA-2026:54622
  • RHSA-2026:48118

Official advisory · high-confidence parse· fetched 6 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, avoid enabling `transferException=true` or `allowJavaSerializedObject=true` on Apache Camel `camel-vertx-http` producer endpoints that communicate with untrusted or network-reachable backend services. Ensure all producer connections utilize TLS (HTTPS) to prevent man-in-the-middle attacks. If enabling these options is necessary, configure a strict deserialization filter using the `-Djdk.serialFilter` JVM system property, for example: `-Djdk.serialFilter="java.**;org.apache.camel.**;!*"`. This will restrict the classes allowed during deserialization, limiting the potential impact.

Official advisory · high-confidence parse· fetched 6 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.