SCA: security update for org.apache.camel:camel-consul (GHSA-5rc6-9qfp-8vwg)

high Tenable Cloud Security Plugin ID 441266

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry
and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store
and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilter. An attacker
who can write to the Consul KV store backing a Camel ConsulRegistry instance could inject a malicious
serialized Java object that is deserialized the next time Camel performs a lookup against that registry,
leading to arbitrary code execution in the Camel process. The issue mirrors the class of vulnerability
already addressed for other Camel components in CVE-2024-22369, CVE-2024-23114 and CVE-2026-25747, and was
overlooked during the original remediation of those CVEs. This issue affects Apache Camel: from 3.0.0
before 4.14.6, from 4.15.0 before 4.18.1. Users are recommended to upgrade to version 4.19.0, which fixes
the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6.
If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.1. (CVE-2026-27172)

Solution

Update the org.apache.camel:camel-consul library and its related packages to version 4.14.6 or later.

See Also

https://github.com/advisories/GHSA-5rc6-9qfp-8vwg

Plugin Details

Severity: High

ID: 441266

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 5/6/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.03

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2026-27172

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/27/2026

Vulnerability Publication Date: 4/27/2026

Reference Information

CVE: CVE-2026-27172

cwe: CWE-502