Severity: 
    CVSS 3.1: 8.8 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected versions:

- Apache Camel Karavan 3.18.0 before 4.22.1

Description:

Improper limitation of a pathname to a restricted directory ('path traversal') 
vulnerability in Apache Camel Karavan.



A project file name supplied through the project file API was used verbatim as 
a path segment when the project was written to the working copy for a Git 
commit, so a name containing `../` sequences caused the file content to be 
written outside the project directory, to any location writable by the Karavan 
process. An authenticated user of any role could use this to overwrite 
application configuration or files on the application classpath and so execute 
code in the Karavan container.



This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1.



Users are recommended to upgrade to version 4.22.1, which fixes the issue.

Solution:

Upgrade to Apache Camel Karavan 4.22.1. Apache Camel Karavan has no maintenance 
branches, so 4.22.1 is the only release containing the fix.

Credit:

CyberLeo (reporter)
Marat Gubaidullin (remediation developer)
Andrea Cosentino (coordinator)

References:

https://camel.apache.org/security/CVE-2026-103412.html
https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf
https://camel.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-103412

Timeline:

2026-08-28: Reported to the Apache Security Team and forwarded to the Apache 
Camel PMC
2026-08-28: Fix committed
2026-09-29: Apache Camel Karavan 4.22.1 released
2026-10-07: Advisory published

Reply via email to