Apache Camel Keycloak Component Vulnerability: Early Warning
An early warning has been issued regarding a high severity vulnerability in the Apache Camel Keycloak Component. Affected parties should assess their exposure and take recommended actions.
What happened
Reportedly, a critical vulnerability has been identified in the Apache Camel Keycloak Component, specifically within the KeycloakSecurityPolicy. This vulnerability, tracked under CVE-2026-23552 and GHSA-QVC3-6Q9X-95PJ, appears to involve improper authentication, missing authentication for critical functions, and a 'failing open' scenario. The KeycloakSecurityPolicy of camel-keycloak is said to guard a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence. The actual cryptographic verification of the bearer access token is performed exclusively inside those role and permission checks. It is under investigation how this vulnerability might be exploited and what the full impact could be.
Professional software engineers using camel-keycloak (maven) are advised to assess their exposure to this vulnerability. The recommended action is to upgrade to a version of camel-keycloak that includes the fix for this vulnerability. For more detailed information, primary sources should be consulted.
How 0Day mitigates this
camel-keycloak is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.