CRITICALMaven →
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage
Affected packages
- org.apache.camel:camel-activemq— 3.0.0 → 4.14.7
- org.apache.camel:camel-activemq6— 3.0.0 → 4.14.7
- org.apache.camel:camel-amqp— 3.0.0 → 4.14.7
- org.apache.camel:camel-jms— 3.0.0 → 4.14.7
- org.apache.camel:camel-sjms— 3.0.0 → 4.14.7
- org.apache.camel:camel-sjms2— 3.0.0 → 4.14.7
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-40860
- https://github.com/apache/camel/pull/22598
- https://github.com/apache/camel/pull/22603
- https://github.com/apache/camel/pull/22604
- https://github.com/apache/camel/pull/22639
- https://github.com/apache/camel/commit/0c06142c46a1422b6b49fab784a1087c50e48ee8
- https://github.com/apache/camel/commit/107e8c279cf9bf488843e33fb6333cc2d7f37c67
- https://github.com/apache/camel/commit/6a82709f0fc5431f46d2939547aacd2c7395c97a
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40860.json
- https://issues.apache.org/jira/browse/CAMEL-23321
- https://github.com/apache/camel/releases/tag/camel-4.20.0
- https://github.com/apache/camel/releases/tag/camel-4.18.2
- https://github.com/apache/camel/releases/tag/camel-4.14.7
- https://github.com/apache/camel
- https://camel.apache.org/security/CVE-2026-40860.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2463172
- https://access.redhat.com/security/cve/CVE-2026-40860
- https://access.redhat.com/errata/RHSA-2026:22453
- https://access.redhat.com/errata/RHSA-2026:17668
- http://www.openwall.com/lists/oss-security/2026/04/26/10
Structured record: https://osv.dev/vulnerability/GHSA-m5vh-3fw5-5wgh
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta