Red Hat Security Advisory: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP2)
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-40983 — micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests CVE-2026-40984 — micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests CVE-2026-49875 — cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
🎯 Affected products1
- Red Hat Build of Apache Camel 4.18 for Quarkus 3.33
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: To mitigate this issue, restrict network access to services exposing Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential for the deployment, consider disabling it entirely to eliminate the attack vector. Any changes to network configurations or service settings may require a service restart to take effect, potentially impacting availability during the transition. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:36839
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/cve/CVE-2026-54513
- externalhttps://access.redhat.com/security/cve/CVE-2026-54512
- externalhttps://access.redhat.com/security/cve/CVE-2026-40983
- externalhttps://access.redhat.com/security/cve/CVE-2026-40984
- externalhttps://access.redhat.com/security/cve/CVE-2026-49875
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486697
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486716
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488309
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492015
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36839.json