Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
Apache Camel Spring Boot
Subscribe
Build Of Apache Camel For Quarkus
Subscribe
Build Of Apache Camel For Spring Boot
Subscribe
Camel Quarkus
Subscribe
Fuse 7
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Expansion Pack
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
|
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xfxp-ppx7-cqrp | camel-infinispan Vulnerable to Deserialization of Untrusted Data |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Thu, 21 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Spring Boot
|
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.18 | |
| Vendors & Products |
Redhat camel Spring Boot
|
Redhat apache Camel Spring Boot
|
| References |
|
Mon, 27 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot Redhat fuse 7 Redhat jboss Enterprise Application Platform Expansion Pack |
|
| Vendors & Products |
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot Redhat fuse 7 Redhat jboss Enterprise Application Platform Expansion Pack |
Thu, 23 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability. | |
| Title | Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization | |
| First Time appeared |
Redhat
Redhat camel Quarkus Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat jbosseapxp |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp |
|
| Vendors & Products |
Redhat
Redhat camel Quarkus Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat jbosseapxp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-21T14:07:32.787Z
Reserved: 2026-04-22T12:43:14.958Z
Link: CVE-2026-6857
Updated: 2026-04-22T13:34:22.726Z
Status : Awaiting Analysis
Published: 2026-04-22T13:16:22.583
Modified: 2026-05-21T15:16:30.200
Link: CVE-2026-6857
OpenCVE Enrichment
Updated: 2026-04-27T20:21:06Z
Github GHSA