https://seclists.org/oss-sec/2026/q3/52: CVE-2026-49365: Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error turned the full Java stack trace in the HTTP sponse body, disclosing sensitive internal information to unauthenticated clients
Published Jul 5, 2026
·Updated
Affected Software
2 affected components
Apache Camel Netty HTTP (camel-netty-http)>4.0.0<=4.14.8, >4.15.0<=4.18.3, >4.19.0<=4.21.0
Apache Apache Camel<4.14.8, <4.18.3, <4.21.0
Frequently Asked Questions
1
What is the severity of CVE-2026-49365?
The severity of CVE-2026-49365 is considered moderate.
2
Which versions of Apache Camel are affected by CVE-2026-49365?
Affected versions include Apache Camel (org.apache.camel:camel-netty-http) 4.0.0 before 4.14.8, 4.15.0 before 4.18.3, and 4.19.0 before 4.21.0.
3
What vulnerability does CVE-2026-49365 describe?
CVE-2026-49365 describes a vulnerability where the muteException consumer option defaulted to false, allowing sensitive internal information to be disclosed to unauthenticated clients.
4
How do I fix CVE-2026-49365?
To fix CVE-2026-49365, upgrade to Apache Camel versions 4.14.8 or later, 4.18.3 or later, or 4.21.0 or later.
5
What risks are associated with CVE-2026-49365?
The risks associated with CVE-2026-49365 include potential data exposure and leakage of sensitive information to unauthorized users.