CVE-2026-56139
Last modified
CVE-2026-56139 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false, whereas the other Camel HTTP server components (camel-http / camel-jetty / camel-servlet and camel-platform-http) default it to true. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false, whereas the other Camel HTTP server components (camel-http / camel-jetty / camel-servlet and camel-platform-http) default it to true. With muteException=false, when a request triggers an exception during route processing the consumer writes the full Throwable stack trace into the HTTP response body as text/plain instead of returning an empty body. Any unauthenticated client that can reach the endpoint and cause a processing error - for example by sending a malformed request body, an invalid parameter, or otherwise triggering a route-internal failure - therefore receives a complete Java stack trace. Such a stack trace can disclose sensitive internal information, including credentials embedded in exception messages, internal host names and IP addresses, filesystem paths, dependency and version details, database and class names, and the application's internal structure, which an attacker can use to plan further attacks. In addition, for Rest DSL consumers the muteException option was not honoured at all: the RestUndertowHttpBinding was created with a hard-coded false, so the stack trace was returned even when muteException=true had been configured. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, set muteException=true explicitly on the camel-undertow consumer (for example undertow: http://0.0.0.0:8080/api?muteException=true , or globally via the camel.component.undertow.mute-exception=true property), so that processing errors no longer return the stack trace to the client; note that on affected releases this workaround does not cover Rest DSL consumers, whose binding ignores the option until the fix is applied.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | >= 4.0.0, < 4.14.8 |
| Apache | Camel | >= 4.15.0, < 4.18.3 |
| Apache | Camel | >= 4.19.0, < 4.21.0 |
References
- https://camel.apache.org/security/CVE-2026-56139.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/05/29Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56139?
How severe is CVE-2026-56139?
How do I fix CVE-2026-56139?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5613A vulnerability was identified in Belkin F9K1015 1.00.10. Th…8.8
- CVE-2026-56130"Remember me" cookie age is not verified on the server. This…2
- CVE-2026-56131libexpat before 2.8.2 lacks handler call depth tracking for …4.9
- CVE-2026-56132In libexpat before 2.8.2, there is a heap-based buffer overf…6.9
- CVE-2026-56137RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. con…8.4
- CVE-2026-56138AIL framework contains a path traversal vulnerability in the…5.3
- CVE-2026-5614A security flaw has been discovered in Belkin F9K1015 1.00.1…8.8
- CVE-2026-56140Improper Input Validation vulnerability in Apache Camel AWS …9.8
- CVE-2026-56141In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.…9.8
- CVE-2026-56142In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.…8.8
- CVE-2026-56144Incorrect Authorization (CWE-863) in Elasticsearch can allow…6.5
- CVE-2026-56145Uncontrolled Resource Consumption (CWE-400) in Elasticsearch…6.5
Are you affected by CVE-2026-56139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
