High severity7.3OSV Advisory· Published Jul 6, 2026· Updated Jul 8, 2026
CVE-2026-49042
CVE-2026-49042
Description
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.camel:camel-langchain4j-toolsMaven | >= 4.8.0, < 4.18.3 | 4.18.3 |
org.apache.camel:camel-langchain4j-toolsMaven | >= 4.19.0, < 4.21.0 | 4.21.0 |
org.apache.camel:camel-langchain4j-agentMaven | >= 4.8.0, < 4.18.3 | 4.18.3 |
org.apache.camel:camel-langchain4j-agentMaven | >= 4.19.0, < 4.21.0 | 4.21.0 |
org.apache.camel:camel-spring-ai-toolsMaven | >= 4.8.0, < 4.18.3 | 4.18.3 |
org.apache.camel:camel-spring-ai-toolsMaven | >= 4.19.0, < 4.21.0 | 4.21.0 |
Affected products
3Patches
Vulnerability mechanics
References
12- www.openwall.com/lists/oss-security/2026/07/06/17nvdThird Party AdvisoryWEB
- camel.apache.org/security/CVE-2026-49042.htmlnvdVendor AdvisoryPatchWEB
- github.com/advisories/GHSA-hh8r-75r6-qrg9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-49042ghsaADVISORY
- github.com/apache/camel/commit/5d0028f6bc7a70556dc1d408b1b6cadb59e1842dghsaWEB
- github.com/apache/camel/commit/6851a94075b82375381a7236e081292b67f6bf9aghsaWEB
- github.com/apache/camel/commit/e9c4541a91ce75ce4817d499e704299c3933edaaghsaWEB
- github.com/apache/camel/pull/23535ghsaWEB
- github.com/apache/camel/pull/23551ghsaWEB
- github.com/apache/camel/releases/tag/camel-4.18.3ghsaWEB
- github.com/apache/camel/releases/tag/camel-4.21.0ghsaWEB
- issues.apache.org/jira/browse/CAMEL-23621ghsaWEB
News mentions
0No linked articles in our index yet.