CVE-2026-103413: Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes.yaml

Published Oct 9, 2026
·
Updated

Improper input validation vulnerability in Apache Camel Karavan.

When a deployment was started, Karavan unmarshalled a project's kubernetes.yaml and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities.

This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1.

Users are recommended to upgrade to version 4.22.1, which fixes the issue.

Affected Software

1 affected component
Apache Camel Karavan>=4.0.0<4.22.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Camel Karavan to a version that resolves this vulnerability.

    Fixed in 4.22.1
  2. Compensating control

    Enforce PodSecurity admission on the namespace where Karavan deploys.

  3. Compensating control

    Restrict the Karavan service account's RBAC permissions to only what Karavan requires.

Event History

Oct 9, 2026
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Apache Camel Karavan versions from 4.0.0 up to, but not including, 4.22.1 are affected. Version 4.22.1 fixes the issue.

2

What access does an attacker need?

An attacker needs to be an authenticated Karavan user; the issue applies to users of any role. Exploitation occurs when a deployment is started for a project whose kubernetes.yaml contains attacker-controlled resources.

3

What is the practical impact of exploitation?

Karavan can apply arbitrary Kubernetes resource kinds using its service account permissions, without pinning a target namespace. This can include pods configured with privileged containers, privilege escalation, added capabilities, host networking or namespaces, hostPath volumes, or host ports.

4

What should be done if an affected version is in use?

Upgrade Apache Camel Karavan to version 4.22.1. Until upgraded, treat deployment of project kubernetes.yaml files as security-sensitive because Karavan applies all resources they contain within the reach of its service account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203