CVE-2026-27172 is an unsafe deserialization vulnerability in the camel-consul component of Apache Camel. The flaw is in org.apache.camel.component.consul.ConsulRegistry, including the inner ConsulRegistryUtils.deserialize method, which reads Java-serialized values from the Consul key-value store and passes them to ObjectInputStream.readObject() without configuring an ObjectInputFilter or equivalent class restrictions. Because deserialization occurs on data retrieved from the backing Consul KV store during registry lookup operations, an attacker who can place crafted serialized content into that store can cause Camel to deserialize a malicious object on a subsequent lookup. This can result in arbitrary code execution within the Camel process. The issue affects Apache Camel versions 3.0.0 before 4.14.6 and 4.15.0 before 4.18.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Spring Boot/Java proof-of-concept reproducer for CVE-2026-27172, a Java deserialization vulnerability in Apache Camel's camel-consul ConsulRegistry. The project is not a scanner or detection script; it actively demonstrates exploitation by exposing REST endpoints that initialize a Consul-backed registry entry, overwrite that entry with attacker-supplied Base64 serialized data, and then trigger Camel's vulnerable lookup path. Repository structure: pom.xml defines a Maven Spring Boot application using Java 17, camel-consul-starter and camel-spring-boot-starter at Camel 4.18.0 (explicitly vulnerable per the README), plus commons-collections 3.2.1 to ensure a gadget chain is present. Application.java is the Spring Boot entry point. ExploitController.java is the main exploit logic and the effective entry point for the PoC. ConsulRegistryRoute.java is intentionally disabled and only documents how a real Camel route would invoke lookupByName() during bean resolution. application.properties sets the web server to port 8080. Main exploit capabilities: ExploitController exposes GET /exploit/init to create a legitimate serialized value in Consul under key myProcessor using ConsulRegistry.put(); POST /exploit/inject to overwrite that same Consul KV key with an attacker-provided Base64 payload; GET /exploit/trigger to call ConsulRegistry.lookupByName("myProcessor"), which causes Base64 decoding and unsafe ObjectInputStream.readObject() deserialization in affected Camel versions; and GET /exploit/cleanup to remove the key. The exploit therefore demonstrates arbitrary code execution through attacker-controlled data in the Consul KV store when the application performs a registry lookup. Attack path: the attacker needs the ability to write to the Consul KV store used by the Camel application. Once a malicious serialized object is stored under a key that Camel resolves, any subsequent lookupByName()/lookupByNameAndType()/findByType* path can deserialize the payload. The README shows a ysoserial-generated CommonsCollections7 payload executing a benign command (touch /tmp/pwned), but the mechanism is generic arbitrary command execution via Java gadget chains. Notable endpoints and targets: the PoC app listens on localhost:8080 and uses a local Consul agent at http://localhost:8500. The specific Consul KV key targeted is myProcessor. The exploit is both web-exposed (through the PoC controller) and network-oriented (through interaction with the Consul service).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.