CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure

Published Jul 6, 2026
·
Updated

Deserialization of Untrusted Data vulnerability in Apache Camel.

The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.;javax.;org.apache.camel.;!', or the no-'javax.' variant in the aggregation-repository components) uses a recursive 'java.' glob that admits classes whose hashCode/equals/readObject methods perform network I/O, notably java.net.URL and java.net.InetAddress. When an attacker can deliver a Java-serialized payload to an affected Camel consumer, deserialization of a HashMap (or any collection that calls hashCode on its elements) containing java.net.URL keys causes the JVM to issue DNS queries to the attacker-supplied host during the deserialization side-effect. The class-level filter check passes because the resulting object's class (HashMap) is allow-listed; the DNS query is observable on an attacker-controlled DNS server, providing an out-of-band side channel. The exposure is highest on the camel-jms family because JmsBinding.extractBodyFromJms invokes ObjectMessage.getObject() unconditionally when mapJmsMessage=true (default). Affected components: camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and the aggregation repository components camel-leveldb, camel-cassandraql, camel-consul, camel-sql (JDBC aggregation repository). This issue affects Apache Camel: from 4.14.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0.

Users are recommended to upgrade to a version that contains the CAMEL-23372 fix once available: 4.21.0 for the 4.21.x line, 4.18.3 for the 4.18.x line, and 4.14.8 for the 4.14.x line. For deployments that cannot upgrade immediately, configure a JMS-provider-side allow-list (Apache ActiveMQ Artemis 'deserializationAllowList' / 'deserializationDenyList', Apache ActiveMQ Classic 'org.apache.activemq.SERIALIZABLEPACKAGES') as the primary mitigation, and/or override the in-code default via the endpoint-level 'deserializationFilter' option or the JVM-wide '-Djdk.serialFilter' system property with an explicit deny: '!java.net.;java.;javax.;org.apache.camel.;!' (or '!java.net.;java.;org.apache.camel.;!' for the aggregation-repository components, which do not include javax.).

Affected Software

4 affected components
Apache Apache Camel>4.14.0<=4.14.8, >4.15.0<=4.18.3, >4.19.0<=4.21.0
Apache Camel>=4.14.0<4.14.8
Apache Camel>=4.18.0<4.18.3
Apache Camel=4.20.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository) to a version that resolves this vulnerability.

    Fixed in 4.21.0
  2. Upgrade

    Upgrade Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository) to a version that resolves this vulnerability.

    Fixed in 4.18.3
  3. Upgrade

    Upgrade Apache Camel (camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and aggregation repositories camel-leveldb, camel-cassandraql, camel-consul, camel-sql JDBC aggregation repository) to a version that resolves this vulnerability.

    Fixed in 4.14.8
  4. Configuration

    For deployments that cannot upgrade immediately, configure the JMS-provider-side deserialization allow/deny lists (Apache ActiveMQ Artemis: deserializationAllowList / deserializationDenyList) as the primary mitigation.

    Apache ActiveMQ Artemis (JMS provider) deserializationAllowList / deserializationDenyList = Use an explicit allow-list and/or deny-list so that java.* and java.net.* are denied (per mitigation guidance).
  5. Configuration

    For deployments that cannot upgrade immediately, configure JMS-provider-side deserialization allow-listing/denying (Apache ActiveMQ Classic: org.apache.activemq.SERIALIZABLE_PACKAGES) as the primary mitigation.

    Apache ActiveMQ Classic (JMS provider) org.apache.activemq.SERIALIZABLE_PACKAGES = Configure the SERIALIZABLE_PACKAGES property to prevent deserialization of java.net.* and related untrusted classes (per mitigation guidance).
  6. Configuration

    For deployments that cannot upgrade immediately, override the in-code default using the endpoint-level 'deserializationFilter' option with an explicit deny filter as follows: '!java.net.**;java.**;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;!*' for aggregation-repository components, which do not include javax.**).

    Apache Camel endpoint (affected components / consumers) deserializationFilter = !java.net.**;java.**;javax.**;org.apache.camel.**;!* (or '!java.net.**;java.**;org.apache.camel.**;!*' for the aggregation-repository components)
  7. Configuration

    For deployments that cannot upgrade immediately, override the default via the JVM-wide system property '-Djdk.serialFilter' using an explicit deny filter: '!java.net.**;java.**;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;!*' for aggregation-repository components).

    JVM (all Camel components in the process) -Djdk.serialFilter = !java.net.**;java.**;javax.**;org.apache.camel.**;!* (or '!java.net.**;java.**;org.apache.camel.**;!*' for the aggregation-repository components)
  8. Compensating control

    If immediate upgrade is not possible, use JMS-provider-side deserialization filtering (Apache ActiveMQ Artemis: deserializationAllowList/deserializationDenyList; Apache ActiveMQ Classic: org.apache.activemq.SERIALIZABLE_PACKAGES) and/or enforce Camel endpoint-level deserializationFilter or JVM-wide -Djdk.serialFilter deny patterns to prevent attacker-supplied Java-serialized payloads from triggering DNS side-channel queries.

Event History

Jul 6, 2026
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42527?

CVE-2026-42527 has a high severity rating of 8.1 according to the CVSS 3.1 scale.

2

How do I fix CVE-2026-42527?

To fix CVE-2026-42527, update your Apache Camel components to implement a more restrictive ObjectInputFilter pattern.

3

What is the risk associated with CVE-2026-42527?

CVE-2026-42527 poses a risk score of 75, indicating a significant threat level due to potential DNS-based information disclosure.

4

What kind of vulnerability is CVE-2026-42527?

CVE-2026-42527 is a deserialization of untrusted data vulnerability affecting Apache Camel.

5

Which software components are affected by CVE-2026-42527?

CVE-2026-42527 affects various components of Apache Camel that utilize the default ObjectInputFilter pattern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203