Red Hat Product Errata RHSA-2026:19835 - Security Advisory Issued: 2026-05-20 Updated: 2026-05-20 RHSA-2026:19835 - Security Advisory Overview Synopsis Critical: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 update is now available (RHBQ 3.27.3.SP2) Type/Severity Security Advisory: Critical Topic An update for Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 update is now available (RHBQ 3.27.3.SP2). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. Red Hat Product Security has rated this update as having a security impact of Critical. Description An update for Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 update is now available (RHBQ 3.27.3.SP2). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: neethi: Apache Neethi: Denial of Service via circular policy references [rhboac-camel-quarkus-3] (CVE-2026-42403) neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API [rhboac-camel-quarkus-3] (CVE-2026-42404) neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization [rhboac-camel-quarkus-3] (CVE-2026-42402) camel-google-pubsub: Apache Camel: Remote Code Execution and Arbitrary File Write via case-variant header injection [rhboac-camel-quarkus-3] (CVE-2026-40453) camel-jms: Apache Camel: Remote Code Execution and Arbitrary File Write via case-variant header injection [rhboac-camel-quarkus-3] (CVE-2026-40453) camel-mail: Camel-Mail: Altered application behavior via header injection [rhboac-camel-quarkus-3] (CVE-2026-33454) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Affected Products Red Hat Build of Apache Camel 1 x86_64 Fixes BZ - 2463173 - CVE-2026-40453 Apache Camel: org.apache.camel: Apache Camel: Remote Code Execution and Arbitrary File Write via case-variant header injection BZ - 2463181 - CVE-2026-33454 Apache Camel: Camel-Mail: Camel-Mail: Altered application behavior via header injection BZ - 2464314 - CVE-2026-42403 org.apache.neethi: Apache Neethi: Denial of Service via circular policy references BZ - 2464315 - CVE-2026-42402 org.apache.neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization BZ - 2464324 - CVE-2026-42404 Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API CVEs CVE-2026-33454 CVE-2026-40453 CVE-2026-42402 CVE-2026-42403 CVE-2026-42404 References https://access.redhat.com/security/updates/classification/#critical The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This critical update addresses multiple vulnerabilities in Red Hat Build of Apache Camel for Quarkus, including three high-severity CVEs (CVE-2026-42402, CVE-2026-42403, CVSS 7.5) and one medium-severity CVE (CVE-2026-42404, CVSS 6.5) in Apache Neethi, which can lead to denial of service, information disclosure, and network access bypass. The affected component is Apache Neethi versions prior to 3.2.2, which is the fixed version. The advisory also resolves critical header injection vulnerabilities in Camel components (CVE-2026-40453, CVE-2026-33454) enabling remote code execution and arbitrary file writes.