CVE-2026-25747 - Vulnerability Analysis
N/aLast Updated: February 23, 2026
Apache Camel LevelDB - Insecure Deserialization
Published: February 23, 2026Updated: February 23, 2026PoC Available
Overview
Apache Camel LevelDB component (4.10.0 < versions < 4.10.9, 4.14.0 < versions < 4.14.5, 4.15.0 < versions < 4.18.0) contains an insecure deserialization vulnerability caused by unfiltered deserialization in DefaultLevelDBSerializer, letting attackers with write access to LevelDB files execute arbitrary code, exploit requires attacker to write crafted serialized objects to LevelDB files.
Severity & Score
Severity: N/a
Impact
Attackers with write access to LevelDB files can execute arbitrary code within the application context, potentially compromising the system.
Mitigation
Upgrade to Apache Camel 4.18.0, or 4.10.9 for 4.10.x LTS, or 4.14.5 for 4.14.x LTS releases.
References
Related Resources
Details
- CVE ID
- CVE-2026-25747
- Severity
- N/a
- Type
- insecure_deserialization
- Status
- unconfirmed
CWE
- CWE-502
CVSS Metrics
N/A