CVE-2026-40473
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
Camel-MINA Vulnerable to Deserialization of Untrusted Data
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@apache.org — https://camel.apache.org/security/CVE-2026-40473.html
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.camel:camel-mina | >=3.0.0,<4.14.6 | 4.14.6 |
| Maven | org.apache.camel:camel-mina | >=4.15.0,<4.18.2 | 4.18.2 |
| Maven | org.apache.camel:camel-mina | >=4.19.0,<4.20.0 | 4.20.0 |
| MAVEN | org.apache.camel:camel-mina | >= 4.19.0, < 4.20.0 | 4.20.0 |
| MAVEN | org.apache.camel:camel-mina | >= 4.15.0, < 4.18.2 | 4.18.2 |
| MAVEN | org.apache.camel:camel-mina | >= 3.0.0, < 4.14.6 | 4.14.6 |
References
- https://camel.apache.org/security/CVE-2026-40473.html
- http://www.openwall.com/lists/oss-security/2026/04/26/8
- https://nvd.nist.gov/vuln/detail/CVE-2026-40473
- https://github.com/apache/camel/pull/22583
- https://github.com/apache/camel/pull/22584
- https://github.com/apache/camel/pull/22585
- https://github.com/apache/camel/commit/8e7f6335d2b4b096df26f8221723405ceaee275a
- https://github.com/apache/camel/commit/b605816d11c253d22989abc290c198be83e3f817
- https://github.com/apache/camel/commit/c35b0a3720f8c80025b06112d5d9c2932426d7f0
- https://github.com/apache/camel
- https://issues.apache.org/jira/browse/CAMEL-23319
- https://github.com/advisories/GHSA-vpr3-2659-rw55
CWEs
CWE-502
Verify integrity in audit chain (admin only). AS-IS.