CVE-2026-40473: Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body ObjectInput), an attacker sending a crafted serialized Java object over the network to the MINA consumer port can trigger arbitrary code execution in the context of the application during readObject().
This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0.
Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel (camel-mina component)to a version that resolves this vulnerability.Fixed in 4.14.6 - Upgrade
Upgrade
Apache Camel (camel-mina component)to a version that resolves this vulnerability.Fixed in 4.18.2 - Upgrade
Upgrade
Apache Camel (camel-mina component)to a version that resolves this vulnerability.Fixed in 4.20.0 - Compensating control
If upgrading is not immediately possible, mitigate exposure by restricting network access to the MINA consumer port(s) used by camel-mina TCP/UDP routes so only trusted clients can reach them.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40473?
CVE-2026-40473 has a high severity due to the potential for remote code execution through unsafe deserialization.
How do I fix CVE-2026-40473?
To fix CVE-2026-40473, upgrade to Apache Camel versions 4.14.7, 4.18.3, or 4.20.1 or later, which address the vulnerability.
What versions of Apache Camel are affected by CVE-2026-40473?
Apache Camel versions 3.0.0 to 4.14.6, 4.15.0 to 4.18.2, and 4.19.0 are affected by CVE-2026-40473.
What are the risks associated with CVE-2026-40473?
The risks associated with CVE-2026-40473 include unauthorized remote access and the execution of malicious code.
Is the MinaConverter.toObjectInput() method safe to use in Apache Camel?
No, the MinaConverter.toObjectInput() method is not safe to use in vulnerable versions of Apache Camel due to unsafe deserialization.