RHSA-2026:54776: Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.GA)
An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.GA).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation [rhboac-camel-quarkus-3] (CVE-2026-56624) libthrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation [rhboac-camel-quarkus-3] (CVE-2026-45112) libthrift: Apache Thrift: Denial of Service via improper handling of highly compressed data [rhboac-camel-quarkus-3] (CVE-2026-48586) org.hl7.fhir.utilities: HAPI FHIR XsltUtilities: XML External Entity injection allows local file disclosure and SSRF [rhboac-camel-quarkus-3] (CVE-2026-55471) org.hl7.fhir.dstu2: HAPI FHIR: Denial of Service via Regular Expression Backtracking in DSTU2 Module [rhboac-camel-quarkus-3] (CVE-2026-55470)
Other sources
Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.GA)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat Build of Apache Camel 4.18 for Quarkus 3.33to a version that resolves this vulnerability.Fixed in RHBQ 3.33.3.GAPatch rhboac-camel-quarkus-3 - Operational
Back up your existing installation (including all applications, configuration files, databases, and database settings) before applying the RHBQ 3.33.3.GA update.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54776?
The severity of RHSA-2026:54776 is high with a score of 7.
How do I fix RHSA-2026:54776?
To fix RHSA-2026:54776, you should update to Red Hat Build of Apache Camel 4.18 for Quarkus 3.33.3.GA.
What vulnerabilities are addressed in RHSA-2026:54776?
RHSA-2026:54776 addresses vulnerabilities related to Server-Side Request Forgery (SSRF).
When was RHSA-2026:54776 published?
RHSA-2026:54776 was published on August 13, 2026.
What software is affected by RHSA-2026:54776?
RHSA-2026:54776 affects Red Hat Build of Apache Camel for Quarkus.