https://seclists.org/oss-sec/2026/q3/52: CVE-2026-49365: Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error turned the full Java stack trace in the HTTP sponse body, disclosing sensitive internal information to unauthenticated clients
Published Jul 5, 2026
·Updated
Affected Software
2 affected components
Apache Camel Netty HTTP (camel-netty-http)>4.0.0<=4.14.8, >4.15.0<=4.18.3, >4.19.0<=4.21.0
Apache Apache Camel<4.14.8, <4.18.3, <4.21.0