CVE-2026-49365
Last modified
CVE-2026-49365 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false because the backing field was an uninitialised primitive boolean (Java's default of false), whereas the other Camel HTTP server components (camel-http / camel-jetty / camel-servlet and camel-platform-http) default it to true. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false because the backing field was an uninitialised primitive boolean (Java's default of false), whereas the other Camel HTTP server components (camel-http / camel-jetty / camel-servlet and camel-platform-http) default it to true. With muteException=false, when a request triggers an exception during route processing the consumer writes the full Throwable stack trace into the HTTP response body as text/plain (via DefaultNettyHttpBinding) instead of returning an empty body. Any unauthenticated client that can reach the endpoint and cause a processing error - for example by sending a malformed request body, an invalid parameter, or otherwise triggering a route-internal failure - therefore receives a complete Java stack trace. Such a stack trace can disclose sensitive internal information, including credentials embedded in exception messages, internal host names and IP addresses, filesystem paths, dependency and version details, database and class names, and the application's internal structure, which an attacker can use to plan further attacks. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, set muteException=true explicitly on the camel-netty-http consumer (for example netty-http: http://0.0.0.0:8080/api?muteException=true , or globally via the camel.component.netty-http.configuration.mute-exception=true property), so that processing errors no longer return the stack trace to the client.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | >= 4.0.0, < 4.14.8 |
| Apache | Camel | >= 4.15.0, < 4.18.3 |
| Apache | Camel | >= 4.19.0, < 4.21.0 |
References
- https://camel.apache.org/security/CVE-2026-49365.htmlVendor Advisory
- https://www.openwall.com/lists/oss-security/2026/07/05/25Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-49365?
How severe is CVE-2026-49365?
How do I fix CVE-2026-49365?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4936IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual T…6.2
- CVE-2026-49360Recce is a data-validation toolkit for enhanced dbt (data bu…7.8
- CVE-2026-49361Apache Fluss versions prior to 0.9.1 configure the Netty Len…7.5
- CVE-2026-49362An unauthenticated remote attacker can create arbitrary dura…7.5
- CVE-2026-49363An unauthenticated remote attacker connecting with the CORE …7.5
- CVE-2026-49364An unauthenticated network-adjacent attacker can leverage di…9.1
- CVE-2026-49366In JetBrains IntelliJ IDEA before 2026.1.1 command injection…7.8
- CVE-2026-49367In JetBrains IntelliJ IDEA before 2026.1.1 command execution…8.8
- CVE-2026-49368In JetBrains YouTrack before 2026.1.13162 stored XSS in proj…5.4
- CVE-2026-49369In JetBrains YouTrack before 2026.1.13162 information disclo…4.3
- CVE-2026-4937IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.0…6
- CVE-2026-49370In JetBrains YouTrack before 2026.1.13162 information disclo…7.5
Are you affected by CVE-2026-49365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
