org.apache.camel:camel-infinispan
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.camel:camel-infinispanpage 1 of 1
- CVE-2026-40858HIGHCVSS 8.8EG 8.8✓ Fixed in 4.20.02026-04-27
vulnerable: 4.19.0
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the…
- CVE-2026-6857HIGHCVSS 7.5EG 7.5✓ Fixed in 4.20.02026-04-22
vulnerable: 2.13.0 ... 4.9.0 (224 versions)
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading …
Check whether org.apache.camel:camel-infinispan is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.camel:camel-infinispan CVEs against the assets you own.
Start Free Scan →