SCA: security update for org.apache.camel:camel-hazelcast (GHSA-xww8-mxqw-m84w)

high Tenable Self-Hosted Container Security Plugin ID 446362

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast
component creates and manages Hazelcast instances using a default configuration that applies no Java
deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied
HazelcastInstance, hazelcastConfigUri, or referenced Config bean is provided - neither Hazelcast's
JavaSerializationFilterConfig nor a Camel-side ObjectInputFilter is configured, so objects received over
the Hazelcast cluster protocol are deserialized inside Hazelcast's own serialization layer
(ObjectInputStream.readObject) before Camel ever processes them. An attacker who can join or otherwise
reach the Hazelcast cluster can publish a crafted serialized Java object that is then deserialized on
every Camel node, resulting in remote code execution. The exposure is present by default and requires no
opt-in endpoint configuration: any route using a hazelcast consumer (hazelcast-topic, hazelcast-queue,
hazelcast-seda, hazelcast-map, hazelcast-multimap, hazelcast-replicatedmap, hazelcast-list, hazelcast-
set), as well as the HazelcastAggregationRepository and HazelcastIdempotentRepository, is affected
whenever the managed instance is created from Camel's default configuration. This issue affects Apache
Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are
recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases
stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then
they are suggested to upgrade to 4.18.3. The fix makes Camel apply a default Hazelcast
JavaSerializationFilterConfig (whitelisting the java., javax. and org.apache.camel. class-name prefixes
and blacklisting java.net.) to instances it creates from its own default configuration, while leaving any
user-supplied Config or HazelcastInstance untouched. For deployments that cannot upgrade immediately,
configure a deserialization filter on the Hazelcast instance (Hazelcast JavaSerializationFilterConfig, or
the JVM-wide system property -Djdk.serialFilter=!java.net.**;java.**;javax.**;org.apache.camel.**;!*) and
enable Hazelcast cluster authentication and TLS to restrict who can reach the cluster. (CVE-2026-43865)

Solution

Update the org.apache.camel:camel-hazelcast library and its related packages to version 4.14.8 or later.

See Also

https://github.com/advisories/GHSA-xww8-mxqw-m84w

Plugin Details

Severity: High

ID: 446362

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/26/2026

Updated: 8/26/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43865

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 7/6/2026

Reference Information

CVE: CVE-2026-43865

cwe: CWE-502