← العودة للجدول
CVE-2026-40860
CVE-2026-40860 — JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding clas
📅 2026-04-27
🔴 Critical 🔥 No NVD Vulnerability Vulnerability CVSS 9.8 🎯 EPSS 0.89%

📋 الوصف الكامل

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer,

💻 الأنظمة المتأثرة

Apache HTTP Server 2.4.x

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-40860

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.20.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←