CVE-2026-43865 is a deserialization-of-untrusted-data vulnerability in Apache Camel's camel-hazelcast component. When Camel creates a managed Hazelcast instance using its own default configuration, rather than a user-supplied HazelcastInstance, configuration URI, or Config bean, it does not configure a Hazelcast Java serialization filter or Camel-side ObjectInputFilter. Hazelcast consequently deserializes cluster-protocol objects through its Java serialization layer before Camel processes them. A party able to join or reach the Hazelcast cluster can submit a crafted serialized Java object that is deserialized on affected Camel nodes. The issue affects Camel versions 4.0.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x. Affected default-managed instances may be used by Hazelcast consumers and by the HazelcastAggregationRepository and HazelcastIdempotentRepository.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-43865, an unsafe deserialization vulnerability in Apache Camel's camel-hazelcast component when Camel creates the Hazelcast instance from its default configuration without a deserialization filter. The project contains a victim Camel route and an attacker component in the same application. Structure and purpose: Application.java is the Spring Boot entry point. VictimRoute.java defines the vulnerable Camel consumer route from hazelcast-queue:cve?queueConsumerMode=Poll, intentionally relying on Camel's default Hazelcast instance creation path. ExploitController.java exposes a GET endpoint /exploit/attack that acts as the attacker: it creates a Hazelcast client, joins cluster name 'dev' at 127.0.0.1:5701, and offers a serialized gadget object into queue 'cve'. Gadget.java constructs a CommonsCollections6-style gadget chain using commons-collections 3.2.1 and reflection into java.util internals; on deserialization it executes /usr/bin/touch /tmp/pwned. application.properties sets the web server to port 8080. Dockerfile and docker-compose.yml package and run the demo in a containerized single-node environment. Main exploit capability: remote code execution via network-reachable Hazelcast cluster deserialization. The exploit does not merely detect the issue; it actively sends a malicious serialized object that is deserialized by the victim's Hazelcast queue consumer before Camel processes it. The PoC verifies success by checking for /tmp/pwned. Operational flow: an operator calls the HTTP endpoint /exploit/attack, which resets any prior proof file, builds the gadget payload, connects to the Hazelcast member as a client, submits the object to the queue, waits briefly for deserialization-triggered execution, and returns whether the proof file exists. This makes the repository both a vulnerable service and an exploit launcher for demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity insecure Java deserialization vulnerability in Apache Camel's camel-hazelcast component. Default-managed Hazelcast instances lack a deserialization filter, allowing a network-reachable attacker with Hazelcast cluster access to trigger remote code execution using crafted serialized objects.
An unsafe Java deserialization remote-code-execution vulnerability in Apache Camel's camel-hazelcast component. Default-managed Hazelcast instances lack deserialization filtering, so crafted serialized objects delivered through the Hazelcast cluster protocol can execute code on affected Camel nodes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.