CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
Deserialization of Untrusted Data vulnerability in Apache Camel.
The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.;javax.;org.apache.camel.;!', or the no-'javax.' variant in the aggregation-repository components) uses a recursive 'java.' glob that admits classes whose hashCode/equals/readObject methods perform network I/O, notably java.net.URL and java.net.InetAddress. When an attacker can deliver a Java-serialized payload to an affected Camel consumer, deserialization of a HashMap (or any collection that calls hashCode on its elements) containing java.net.URL keys causes the JVM to issue DNS queries to the attacker-supplied host during the deserialization side-effect. The class-level filter check passes because the resulting object's class (HashMap) is allow-listed; the DNS query is observable on an attacker-controlled DNS server, providing an out-of-band side channel. The exposure is highest on the camel-jms family because JmsBinding.extractBodyFromJms invokes ObjectMessage.getObject() unconditionally when mapJmsMessage=true (default). Affected components: camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and the aggregation repository components camel-leveldb, camel-cassandraql, camel-consul, camel-sql (JDBC aggregation repository). This issue affects Apache Camel: from 4.14.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0.
Users are recommended to upgrade to a version that contains the CAMEL-23372 fix once available: 4.21.0 for the 4.21.x line, 4.18.3 for the 4.18.x line, and 4.14.8 for the 4.14.x line. For deployments that cannot upgrade immediately, configure a JMS-provider-side allow-list (Apache ActiveMQ Artemis 'deserializationAllowList' / 'deserializationDenyList', Apache ActiveMQ Classic 'org.apache.activemq.SERIALIZABLEPACKAGES') as the primary mitigation, and/or override the in-code default via the endpoint-level 'deserializationFilter' option or the JVM-wide '-Djdk.serialFilter' system property with an explicit deny: '!java.net.;java.;javax.;org.apache.camel.;!' (or '!java.net.;java.;org.apache.camel.;!' for the aggregation-repository components, which do not include javax.).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository)to a version that resolves this vulnerability.Fixed in 4.21.0 - Upgrade
Upgrade
Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository)to a version that resolves this vulnerability.Fixed in 4.18.3 - Upgrade
Upgrade
Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository)to a version that resolves this vulnerability.Fixed in 4.14.8 - Configuration
For deployments that cannot upgrade immediately, configure the JMS-provider-side deserialization allow/deny lists (Apache ActiveMQ Artemis: deserializationAllowList / deserializationDenyList) as the primary mitigation.
Apache ActiveMQ Artemis (JMS provider) deserializationAllowList / deserializationDenyList = Use an explicit allow-list and/or deny-list so that java.* and java.net.* are denied (per mitigation guidance). - Configuration
For deployments that cannot upgrade immediately, configure JMS-provider-side deserialization allow-listing/denying (Apache ActiveMQ Classic: org.apache.activemq.SERIALIZABLE_PACKAGES) as the primary mitigation.
Apache ActiveMQ Classic (JMS provider) org.apache.activemq.SERIALIZABLE_PACKAGES = Configure the SERIALIZABLE_PACKAGES property to prevent deserialization of java.net.* and related untrusted classes (per mitigation guidance). - Configuration
For deployments that cannot upgrade immediately, override the in-code default using the endpoint-level 'deserializationFilter' option with an explicit deny filter as follows: '!java.net.**;java.**;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;!*' for aggregation-repository components, which do not include javax.**).
Apache Camel endpoint (affected components / consumers) deserializationFilter = !java.net.**;java.**;javax.**;org.apache.camel.**;!* (or '!java.net.**;java.**;org.apache.camel.**;!*' for the aggregation-repository components) - Configuration
For deployments that cannot upgrade immediately, override the default via the JVM-wide system property '-Djdk.serialFilter' using an explicit deny filter: '!java.net.**;java.**;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;!*' for aggregation-repository components).
JVM (all Camel components in the process) -Djdk.serialFilter = !java.net.**;java.**;javax.**;org.apache.camel.**;!* (or '!java.net.**;java.**;org.apache.camel.**;!*' for the aggregation-repository components) - Compensating control
If immediate upgrade is not possible, use JMS-provider-side deserialization filtering (Apache ActiveMQ Artemis: deserializationAllowList/deserializationDenyList; Apache ActiveMQ Classic: org.apache.activemq.SERIALIZABLE_PACKAGES) and/or enforce Camel endpoint-level deserializationFilter or JVM-wide -Djdk.serialFilter deny patterns to prevent attacker-supplied Java-serialized payloads from triggering DNS side-channel queries.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42527?
CVE-2026-42527 has a high severity rating of 8.1 according to the CVSS 3.1 scale.
How do I fix CVE-2026-42527?
To fix CVE-2026-42527, update your Apache Camel components to implement a more restrictive ObjectInputFilter pattern.
What is the risk associated with CVE-2026-42527?
CVE-2026-42527 poses a risk score of 75, indicating a significant threat level due to potential DNS-based information disclosure.
What kind of vulnerability is CVE-2026-42527?
CVE-2026-42527 is a deserialization of untrusted data vulnerability affecting Apache Camel.
Which software components are affected by CVE-2026-42527?
CVE-2026-42527 affects various components of Apache Camel that utilize the default ObjectInputFilter pattern.