Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103412— Apache Camel Karavan: project file name path traversal when committing a project to Git

Quick assessment

Affected
Apache Software Foundation Apache Camel Karavan
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Camel Karavan 中存在路径遍历漏洞,即对受限目录的路径名限制不当。 当项目通过项目文件 API 提供的文件名被直接用作路径段时,若文件名中包含 序列,则可能导致文件内容被写入项目目录之外的任意位置,这些位置只要是 Karavan 进程具有写入权限即可。具有任何角色的认证用户均可利用此漏洞覆盖应用程序配置文件或类路径上的文件,从而在 Karavan 容器中执行代码。 此漏洞影响 Apache Camel Karavan 从 3.18.0 到 4.22.1(不含)版本。 建议用户升级至修复该问

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103412

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Camel Karavan: project file name path traversal when committing a project to Git
Source: CVE Program / CVE List V5
Vulnerability Description
Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container. This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Camel Karavan 3.18.0 ~ 4.22.1 -

II. Public POCs for CVE-2026-103412

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103412

请登录查看更多情报信息。

Other References for CVE-2026-103412 (2)

Same Patch Batch · Apache Software Foundation · 2026-10-09 · 13 CVEs total

CVE-2026-103413 8.8 HIGH Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes
CVE-2026-108039 Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element and
CVE-2026-107938 Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.
CVE-2026-107937 Apache CXF: The attachment header size and count limits can be bypassed, which allows deni
CVE-2026-100227 Apache CXF: XML Signature wrapping in JAX-RS XML Security
CVE-2026-97791 Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares valid
CVE-2026-97468 Apache CXF: Authentication bypass via weak cache keys for validated STS tokens
CVE-2026-86463 Apache CXF: FIQL Query Parser Denial of Service
CVE-2026-79650 Apache CXF: OIDC RP Open Redirect
CVE-2026-78384 Apache CXF: Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing (Decompres
CVE-2026-73179 Apache CXF: JPA authorization-code consume is non-atomic
CVE-2026-71575 Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFil

IV. Related Vulnerabilities

V. Comments for CVE-2026-103412

No comments yet


Leave a comment