SCA: security update for org.apache.camel:camel-keycloak (GHSA-qvc3-6q9x-95pj)

critical Tenable Self-Hosted Container Security Plugin ID 445318

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing
Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak
guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in
sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty -
validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The
actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local
JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and
permission checks. KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which
is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are
skipped and the access token is therefore never verified. The token-presence check still rejects a missing
token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header -
including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the
protected route, with no signature, issuer or expiry check and no request to Keycloak. The token is read
from the inbound request header because allowTokenFromHeader defaults to true. Because the normal reason
to place a route behind this policy is that the route performs server-side work, the bypass results in
unauthenticated access to that work; where the protected route forwards to a code-execution-capable
producer, it can result in unauthenticated remote code execution. This defect is independent of
CVE-2026-23552: that issue concerned the issuer claim and was fixed by adding a check inside the
verification routine, but here the verification routine is not reached at all in the default
configuration, so the defect remains. This issue affects Apache Camel: from 4.15.0 before 4.18.3, from
4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users
are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that
cannot upgrade immediately, configure a non-empty requiredRoles or requiredPermissions on every
KeycloakSecurityPolicy so that the token-verification path is exercised, set allowTokenFromHeader to false
where the token is not expected from the request header, or perform token verification at the framework
layer ahead of the policy. (CVE-2026-53913)

Solution

Update the org.apache.camel:camel-keycloak library and its related packages to version 4.18.3 or later.

See Also

https://github.com/advisories/GHSA-qvc3-6q9x-95pj

Plugin Details

Severity: Critical

ID: 445318

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/24/2026

Updated: 7/24/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.4

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53913

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 7/6/2026

Reference Information

CVE: CVE-2026-53913

cwe: CWE-287