Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Camel
APPApache2.22.0 – 2.25.03.0.0 – 3.1.0Oracle Communications Diameter Signaling Router
APPOracle8.0.0 – 8.5.0Oracle Enterprise Manager Base Platform
APPOracle13.3.0.013.4.0.0Oracle Flexcube Private Banking
APPOracle12.0.012.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References
Related vulnerabilities
CVE-2020-2555CRITICAL9.8⚠ KEVPL ✓same product
RCE przez deserializację w Oracle Coherence via protokół T3
CVE-2017-9841CRITICAL9.8⚠ KEVPL ✓same product
RCE w PHPUnit — wykonanie kodu PHP przez eval-stdin.php
CVE-2026-71300CRITICAL9.8same product
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects ...
CVE-2026-66906CRITICAL9.1same product
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apac...
CVE-2026-78329CRITICAL9.8same product
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel...