top of page
perceptive_background_267k.jpg

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values v…

Published:

26 april 2026 om 22:00:00

Alert date:

27 april 2026 om 17:03:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Supply Chain & Dependencies

CVE-2026-40860 is a critical remote code execution vulnerability in Apache Camel's JMS components. The vulnerability occurs in JmsBinding.extractBodyFromJms() which deserializes incoming JMS ObjectMessage payloads without proper filtering. When mapJmsMessage option is enabled (default) and Camel acts as JMS consumer, attackers can publish crafted ObjectMessages to achieve RCE. Multiple Camel JMS components are affected including camel-jms, camel-sjms, camel-amqp, camel-activemq. Versions 3.0.0 to 4.14.6, 4.15.0 to 4.18.1, and 4.19.0 to 4.19.x are vulnerable. Fixed versions are 4.20.0, 4.14.7, and 4.18.2.

Technical details

Mitigation steps:

Affected products:

Apache Camel
camel-jms
camel-sjms
camel-sjms2
camel-amqp
camel-activemq
camel-activemq6

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page