GHSA-4xwx-hvv7-7prj
HIGHCVE-2026-40858The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that, when read during normal aggregation repository operations such as
- Affected
- >= 4.0.0, < 4.14.7
- Fixed in
- 4.14.7
- Weakness
- CWE-502
- Published
- 2026-04-27
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference