SCA: security update for org.apache.camel:camel-activemq, org.apache.camel:camel-activemq6, org.apache.camel:camel-amqp, org.apache.camel:camel-jms, org.apache.camel:camel-sjms, org.apache.camel:camel-sjms2 (GHSA-f755-xp6r-8q84)

high Tenable Self-Hosted Container Security Plugin ID 446371

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component.
JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes
the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() whenever the
mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer. The CVE-2026-40860
hardening added a post-deserialization class check that rejects classes outside the default allow-list
java.**;javax.**;org.apache.camel.**;!*. However org.apache.camel.support.DefaultExchangeHolder itself
lives in the allow-listed org.apache.camel.** namespace, so an ObjectMessage whose top-level object is a
DefaultExchangeHolder passes the check. The receiving side then calls DefaultExchangeHolder.unmarshal() on
it without requiring the transferExchange option to be enabled - an asymmetric trust boundary, since the
sending side gates ObjectMessage and transferExchange handling but the receiving side did not - writing
every non-null field of the holder into the Exchange: the message body, the IN and OUT headers, the
exchange properties, the variables, the exchange id and the exception. An attacker who can publish an
ObjectMessage to a queue or topic consumed by an affected Camel application can therefore inject arbitrary
Exchange state using only universally-trusted java.lang and java.util types, with no deserialization
gadget chain required, to manipulate routing and headers, exchange properties and error handling. The same
handling applies to camel-sjms and camel-sjms2, and to the JMS-family components built on JmsComponent and
JmsBinding: camel-amqp, camel-activemq and camel-activemq6. This is a bypass of the CVE-2026-40860 fix
rather than a flaw in it. This issue affects Apache Camel: from 3.0.0 before 4.14.8, from 4.15.0 before
4.18.3, from 4.19.0 before 4.21.0; Apache Camel: from 3.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from
4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users
are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the
4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, JMS ObjectMessage
handling is disabled by default in camel-jms, camel-sjms and the JMS-family components (a new
objectMessageEnabled option defaults to false at the component and endpoint level), so an incoming
ObjectMessage - including a DefaultExchangeHolder payload - is no longer deserialized unless the option is
explicitly enabled; only set objectMessageEnabled=true when the consumed JMS destination is fed
exclusively by trusted producers. For deployments that cannot upgrade immediately, restrict publish access
to the queues and topics consumed by Camel to trusted producers via JMS broker authorization, and do not
expose JMS consumers that map ObjectMessage bodies to untrusted networks; a JMS-provider deserialization
allow-list does not mitigate this specific bypass because the crafted payload uses only universally-
trusted classes. (CVE-2026-43866)

Solution

Update the org.apache.camel:camel-activemq library and its related packages to version 4.14.8 or later.

See Also

https://github.com/advisories/GHSA-f755-xp6r-8q84

Plugin Details

Severity: High

ID: 446371

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/26/2026

Updated: 8/26/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.52

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-43866

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 7/6/2026

Reference Information

CVE: CVE-2026-43866

cwe: CWE-502