Apache Camel Components Vulnerable to Unsafe Deserialization
- Severity
- HIGH
- Affected component
- camel-jms (maven)
- Patched version
- 4.20.0
Apache Camel components camel-jms, camel-sjms, camel-sjms2, camel-amqp, camel-activemq, and camel-activemq6 are reportedly vulnerable to unsafe deserialization of JMS ObjectMessage, which may allow remote code execution.
What happened
Apache Camel components camel-jms, camel-sjms, camel-sjms2, camel-amqp, camel-activemq, and camel-activemq6 are under investigation for a vulnerability that allows unsafe deserialization of JMS ObjectMessage. This vulnerability, tracked as GHSA-M5VH-3FW5-5WGH and CVE-2026-40860, may enable remote code execution. The affected versions are those before 4.14.7, 4.18.2, and 4.20.0. This issue was first flagged on 2026-04-27T09:34:39+00:00.
To assess your exposure, check if your system uses any of the affected Apache Camel components in the specified version ranges. If so, you may be at risk.
What to do about it
- Upgrade to Apache Camel version 4.20.0 to mitigate the vulnerability.
- If you are using the 4.14.x or 4.18.x release streams, upgrade to 4.14.7 or 4.18.2 respectively.
- Monitor the primary sources for updates on the vulnerability and any additional mitigation steps.
- Review your system for any use of the affected Apache Camel components and take appropriate action based on the version you are using.
How 0Day would have caught this
camel-jms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using Apache Camel components camel-jms, camel-sjms, camel-sjms2, camel-amqp, camel-activemq, or camel-activemq6 in versions before 4.14.7, 4.18.2, and 4.20.0.
What should I do right now?
Upgrade to Apache Camel version 4.20.0 or, if on the 4.14.x or 4.18.x release streams, upgrade to 4.14.7 or 4.18.2 respectively.
Is there an official fix available?
Yes, the patched version is 4.20.0 for all affected components.