Skip to main content

Threats Tagged 'cve-2026-42527'

View all threats tagged with 'cve-2026-42527'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-42527

Threats Tagged 'cve-2026-42527'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat build of Apache Camel 4.18.4 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050) * rhaf-camel-spring-boot-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting (CVE-2026-66274) * jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation (CVE-2026-56624) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage (CVE-2026-66909) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider (CVE-2026-68079) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization Code Replay via Race Condition (CVE-2026-57818) * cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation (CVE-2026-57817) * camel: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers (CVE-2026-46457) * camel: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers (CVE-2026-46456) * camel: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields (CVE-2026-48203) * camel-amqp: Apache Camel: Information disclosure via deserialization of untrusted data (CVE-2026-42527) * proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation (CVE-2026-66273) * proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching (CVE-2026-66257) * netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder (CVE-2026-73507) * micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing (CVE-2026-59296) * cxf-rt-rs-security-oauth2: Apache CXF: Security bypass due to improper handling of authorization parameters (CVE-2026-63687) * camel-knative: Apache Camel Knative: Header injection vulnerability allows server-side request forgery (CVE-2026-63621) * camel-main: Apache Camel: Improper authentication allows JWT bypass in Platform HTTP Main component (CVE-2026-66908) * netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243) * httpclient5-cache: Apache HttpComponents Client: Denial of Service due to connection leak (CVE-2026-64607) * jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * zstd-jni: zstd-jni: Data corruption or denial of service via use-after-free vulnerability (CVE-2026-87825) * zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service (CVE-2026-87877) * zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (CVE-2026-87824) * zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795) * zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046) * jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing (CVE-2026-68497) * zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress (CVE-2026-90560) * bcprov-jdk18on: Bouncy Castle for Java: Denial of Service via quadratic-time escaping of X.500 distinguished names (CVE-2026-58059) * bcprov-jdk18on: Bouncy Castle for Java: Cryptographic signature bypass in RSA PKCS#1 verification (CVE-2026-12860) * zstd-jni: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing (CVE-2026-90852) * netty-transport-sctp: Netty: Denial of Service via SCTP memory exhaustion (CVE-2026-59902) * camel-mail: Apache Camel: Injected MIME headers can manipulate route behavior (CVE-2026-59230) * netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext (CVE-2026-75595)

Join the discussion

Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a recursive 'java.**' glob that admits classes whose hashCode/equals/readObject methods perform network I/O, notably java.net.URL and java.net.InetAddress. When an attacker can deliver a Java-serialized payload to an affected Camel consumer, deserialization of a HashMap (or any collection that calls hashCode on its elements) containing java.net.URL keys causes the JVM to issue DNS queries to the attacker-supplied host during the deserialization side-effect. The class-level filter check passes because the resulting object's class (HashMap) is allow-listed; the DNS query is observable on an attacker-controlled DNS server, providing an out-of-band side channel. The exposure is highest on the camel-jms family because JmsBinding.extractBodyFromJms invokes ObjectMessage.getObject() unconditionally when mapJmsMessage=true (default). Affected components: camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and the aggregation repository components camel-leveldb, camel-cassandraql, camel-consul, camel-sql (JDBC aggregation repository). This issue affects Apache Camel: from 4.14.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to a version that contains the CAMEL-23372 fix once available: 4.21.0 for the 4.21.x line, 4.18.3 for the 4.18.x line, and 4.14.8 for the 4.14.x line. For deployments that cannot upgrade immediately, configure a JMS-provider-side allow-list (Apache ActiveMQ Artemis 'deserializationAllowList' / 'deserializationDenyList', Apache ActiveMQ Classic 'org.apache.activemq.SERIALIZABLE_PACKAGES') as the primary mitigation, and/or override the in-code default via the endpoint-level 'deserializationFilter' option or the JVM-wide '-Djdk.serialFilter' system property with an explicit deny: '!java.net.**;java.**;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;!*' for the aggregation-repository components, which do not include javax.**).

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-42527
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses