CVE-2026-103413: Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes.yaml
Improper input validation vulnerability in Apache Camel Karavan.
When a deployment was started, Karavan unmarshalled a project's kubernetes.yaml and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities.
This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1.
Users are recommended to upgrade to version 4.22.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel Karavanto a version that resolves this vulnerability.Fixed in 4.22.1 - Compensating control
Enforce PodSecurity admission on the namespace where Karavan deploys.
- Compensating control
Restrict the Karavan service account's RBAC permissions to only what Karavan requires.
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Camel Karavan versions from 4.0.0 up to, but not including, 4.22.1 are affected. Version 4.22.1 fixes the issue.
What access does an attacker need?
An attacker needs to be an authenticated Karavan user; the issue applies to users of any role. Exploitation occurs when a deployment is started for a project whose kubernetes.yaml contains attacker-controlled resources.
What is the practical impact of exploitation?
Karavan can apply arbitrary Kubernetes resource kinds using its service account permissions, without pinning a target namespace. This can include pods configured with privileged containers, privilege escalation, added capabilities, host networking or namespaces, hostPath volumes, or host ports.
What should be done if an affected version is in use?
Upgrade Apache Camel Karavan to version 4.22.1. Until upgraded, treat deployment of project kubernetes.yaml files as security-sensitive because Karavan applies all resources they contain within the reach of its service account.