CVE-2026-42527 is a deserialization-of-untrusted-data vulnerability in Apache Camel components that use an overly permissive default ObjectInputFilter allow-list. The recursive java.** pattern permits java.net.URL and java.net.InetAddress classes, whose deserialization-related methods can perform network I/O. A serialized collection such as a HashMap containing URL objects can cause hashCode processing during deserialization, resulting in DNS resolution of an attacker-controlled hostname. The class filter permits the operation because the containing collection class is allow-listed. Affected versions are Apache Camel 4.14.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x. Affected components include camel-jms, camel-sjms, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-infinispan, and specified aggregation repositories.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-42527 in Apache Camel. It is a real exploit PoC, not just documentation, and demonstrates an unsafe deserialization side effect rather than remote code execution. The core issue is Camel's permissive default ObjectInputFilter pattern (java.**;javax.**;org.apache.camel.**;!*) in affected versions, which allows java.net.URL objects. When a crafted serialized HashMap containing a URL key is deserialized, HashMap.readObject() recomputes the key hash, invoking URL.hashCode(), which performs hostname resolution and causes an attacker-observable DNS lookup. Repository structure is compact and purpose-built. Application.java is the Spring Boot entry point. MinaObjectRoute.java defines the embedded vulnerable victim service: a Camel MINA TCP consumer bound to 0.0.0.0:5555 that converts incoming bytes to ObjectInput and calls readObject(). PayloadFactory.java builds the malicious serialized payload using the classic URLDNS technique, reflectively manipulating URL.hashCode cache state so the DNS lookup occurs only on the victim side. ExploitController.java exposes a GET endpoint at /exploit/inject on port 8080; when called, it generates the payload, opens a socket to 127.0.0.1:5555, sends the serialized bytes, then reports whether the DNS side channel fired. ExfilResolverProvider.java and ExfilLog.java implement an offline observation mechanism using the JDK InetAddressResolverProvider SPI to intercept and log lookups for hostnames containing the marker 'attacker', avoiding the need for a real external DNS server. The service registration file under META-INF/services enables automatic loading of that resolver provider. The exploit capability is therefore: deliver attacker-controlled serialized data to a vulnerable Camel deserialization path and induce a DNS lookup to an attacker-chosen hostname, proving blind SSRF / out-of-band information disclosure. The PoC is operational because it includes payload generation, delivery, and verification logic, but it is not weaponized and does not include a customizable post-exploitation framework. Supporting files include pom.xml specifying Spring Boot and camel-mina 4.18.2, application.properties setting server.port=8080, and Docker/Docker Compose files for containerized execution. The README thoroughly documents affected versions, vulnerable and fixed filter patterns, reproduction steps, and mitigations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.