CVE-2026-40858 is a high-severity unsafe deserialization vulnerability in the Apache Camel camel-infinispan component. The flaw is in the ProtoStream-based remote aggregation repository, which deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying an ObjectInputFilter. Because untrusted serialized Java objects can be read during normal repository operations such as get or recover, an attacker who is able to write crafted serialized data into the Infinispan cache can cause arbitrary code execution in the context of the Camel application. The issue affects Apache Camel versions 4.0.0 before 4.14.7, 4.15.0 before 4.18.2, and 4.19.0 before 4.20.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot proof-of-concept for CVE-2026-40858, an unsafe deserialization vulnerability in Apache Camel's camel-infinispan remote aggregation repository. It is not just documentation: the code stands up a vulnerable application, connects it to a remote Infinispan cache over HotRod, stores a crafted Exchange containing a CommonsCollections6 gadget, and then triggers Camel's deserialization path via repo.get(), resulting in command execution. Repository structure is small and focused: Application.java is the Spring Boot entry point; InfinispanRepoService.java builds the authenticated HotRod client, creates/opens the remote cache named camel-aggregation, and starts InfinispanRemoteAggregationRepository; Gadget.java constructs a CommonsCollections6-style gadget chain using commons-collections 3.2.1 and reflective access into java.util internals; ExploitController.java exposes GET /exploit/attack, resets the proof file, adds a malicious Exchange under key victim-key, then reads it back to trigger readObject() and verify RCE by checking /tmp/pwned. application.properties binds the app to port 8080. docker-compose.yml launches an Infinispan server on port 11222 with demo credentials admin/password. Main exploit capability: remote code execution through attacker-controlled serialized data in the backing Infinispan cache. The exploit path is network-accessible in realistic deployments because the vulnerable application reads from a remote cache; in this PoC, the web endpoint /exploit/attack orchestrates the attack locally for reproducibility. The payload is operational but basic and hardcoded: it executes /usr/bin/touch /tmp/pwned via Runtime.exec during Java deserialization. This makes the repository an operational PoC rather than a detection script or fake exploit.
Repository contains a multi-PoC assessment for three Apache Camel 4.18.0 vulnerabilities, not a framework module. Structure is split into per-CVE Java applications under poc/cve-2026-33453-coap, poc/cve-2026-40473-mina, and poc/cve-2026-40858-infinispan; a docker-compose lab that exposes the vulnerable services; and three Python exploit scripts under poc/exploits. README.md and EXPLOITS-REPORT.md document root cause, attack flow, and reproduction steps. Main exploit capabilities: - CVE-2026-33453: exploit_cve_2026_33453_coap.py crafts raw CoAP UDP packets and injects CamelExecCommandExecutable/CamelExecCommandArgs as URI query parameters to override camel-exec behavior on /api/status. It is a direct unauthenticated network RCE PoC and parses CoAP responses to display command output. - CVE-2026-40473: exploit_cve_2026_40473_mina.py targets MINA TCP endpoints, especially raw TCP on 9879, and uses ysoserial-generated gadget chains for unsafe Java deserialization. It includes a callback listener to capture command output via HTTP POST/curl from the victim. The Java helper MinaGadgetGenerator builds MINA-compatible serialized gadget bytes, and MinaTestPayload validates wire compatibility. - CVE-2026-40858: exploit_cve_2026_40858_infinispan.py builds a Hot Rod PUT request to write malicious serialized bytes into an Infinispan cache entry used by Camel aggregation. This is a delayed-trigger exploit: code execution occurs when Camel later deserializes the cached object. It can use ysoserial if available or a demo serialized object otherwise. Repository purpose: to demonstrate exploitability of three claimed Apache Camel 4.18.0 issues in a controlled Docker lab. The Java apps intentionally expose vulnerable routes, while the Python scripts operationalize exploitation over UDP/TCP/cache protocols. The code is coherent, aligned with the documented CVEs, and clearly intended as working proof-of-concept exploit material rather than mere detection.
Repository is a multi-PoC research project for three Apache Camel 4.18.0 vulnerabilities, not a framework module. Structure is split into: (1) README and exploit report documenting root cause and reproduction, (2) three Java/Maven vulnerable demo applications under poc/cve-* with Dockerfiles, (3) docker-compose.yml to launch the lab, and (4) three Python exploit scripts under poc/exploits. The CoAP PoC demonstrates unauthenticated header injection over UDP/5683 by crafting raw CoAP packets with URI query parameters that become Camel headers, overriding camel-exec command settings and returning command output. The MINA PoC demonstrates unsafe Java deserialization over TCP on ports 9877/9878/9879; the most important path is 9879 with allowDefaultCodec=false, where raw IoBuffer data is converted into ObjectInputStream without filtering. Supporting Java utilities generate MINA-compatible serialized payloads and test framing. The Python MINA exploit can use ysoserial gadget chains and starts a local HTTP listener to capture exfiltrated command output via curl from the target. The Infinispan PoC demonstrates cache poisoning against a Camel aggregation repository backed by Infinispan; the Python exploit crafts a Hot Rod PUT request to write a malicious serialized object to a predictable cache key, relying on later deserialization by Camel to trigger execution. Overall, this is a real exploit repository with operational PoCs, local lab infrastructure, and clear network targets: CoAP UDP/5683, MINA TCP/9877-9879, and Infinispan Hot Rod TCP/11222.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary code execution vulnerability in Apache Camel's camel-infinispan component caused by deserialization of untrusted data.
An arbitrary code execution vulnerability in Apache Camel camel-infinispan via deserialization of untrusted data.
A high-severity unsafe deserialization vulnerability in Apache Camel's camel-infinispan component ProtoStream remote aggregation repository that can lead to arbitrary code execution if an attacker can write crafted serialized objects to the remote Infinispan cache.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.