VYPR

Maven package

org.apache.camel/camel-infinispan

pkg:maven/org.apache.camel/camel-infinispan

Vulnerabilities (2)

  • CVE-2026-42527HigJul 6, 2026
    affected >= 4.14.0, < 4.14.8fixed 4.14.8

    Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggr

  • CVE-2026-40858HigApr 27, 2026
    affected >= 4.0.0, < 4.14.7fixed 4.14.7

    The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applica