THREAT OPS › Threat News › [NVD] CVE-2026-40858 (HIGH 8.8) — The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applica
[NVD] CVE-2026-40858 (HIGH 8.8) — The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applica
CVE-2026-40858 CVSS: 8.8 HIGH Published: 2026-04-27T10:16:09.627
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that,
Indicators of compromise
- CVE-2026-40858cve
- CVE-2024-22369cve
- CVE-2024-23114cve
- CVE-2026-25747cve
- https://issues.apache.org/jira/browse/CAMEL-23322url
- java.iodomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40858