CRITICALMaven →
Camel-PQC Vulnerable to Deserialization of Untrusted Data
Camel-PQC Vulnerable to Deserialization of Untrusted Data
Affected packages
- org.apache.camel:camel-pqc— before 4.18.2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-40048
- https://github.com/apache/camel/pull/22034
- https://github.com/apache/camel/pull/22495
- https://github.com/apache/camel/commit/5bdd0f1d3289dfa78116deec6c81083708bf432d
- https://github.com/apache/camel/commit/5f87a86f4e337efc59248d278c6a5650e73b3b7c
- https://camel.apache.org/security/CVE-2026-40048.html
- https://github.com/apache/camel
- https://issues.apache.org/jira/browse/CAMEL-23200
- http://www.openwall.com/lists/oss-security/2026/04/26/6
Structured record: https://osv.dev/vulnerability/GHSA-v3vg-332r-mw99
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta