CVE-2026-43866 is a deserialization-of-untrusted-data vulnerability in Apache Camel JMS-related components. When Camel consumes JMS messages with mapJmsMessage enabled, JmsBinding deserializes an incoming ObjectMessage. The class filtering introduced for CVE-2026-40860 permits DefaultExchangeHolder because it resides in the allowed Apache Camel namespace. The consumer then unmarshals that holder without requiring transferExchange to be enabled. This permits an attacker to supply non-null Exchange fields, including the message body, IN and OUT headers, properties, variables, exchange identifier, and exception state. The issue affects camel-jms, camel-sjms, camel-sjms2, and JMS-family components using the affected binding behavior, including camel-amqp, camel-activemq, and camel-activemq6, in versions 3.0.0 through before 4.14.8, 4.15.0 through before 4.18.3, and 4.19.0 through before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot proof-of-concept for CVE-2026-43866, a bypass of Apache Camel’s earlier CVE-2026-40860 deserialization filtering in JMS-family components. It is not a framework module; it is a standalone reproducer composed of a Spring Boot app, Camel JMS route, attacker controller, and Dockerized ActiveMQ Artemis broker. Structure and purpose: Application.java is the Spring Boot entry point. JmsConfig.java configures an ActiveMQConnectionFactory with broker credentials and a realistic trusted package allow-list (java, javax, org.apache.camel), then exposes a Camel jms component. VictimRoute.java defines the vulnerable consumer route from("jms:queue:cve") and records the body/header/property actually observed by the route. CapturedState.java stores those observed values for later reporting. ForgedHolderFactory.java creates the malicious payload by constructing a Camel Exchange and marshaling it into a DefaultExchangeHolder using Camel’s public API. ExploitController.java exposes GET /exploit/attack, which generates a marker, builds the forged holder, opens a JMS connection, sends it as an ObjectMessage to queue cve, waits for the victim route to consume it, and returns a textual proof showing whether body/header/property injection succeeded. Dockerfile and docker-compose.yml package the app and launch an Artemis broker plus the reproducer service. Main exploit capability: the exploit does not attempt code execution. Instead, it performs Exchange-state injection by abusing the fact that a top-level org.apache.camel.support.DefaultExchangeHolder passes Camel’s post-deserialization allow-list and is then unmarshaled into the receiving Exchange. The payload uses only trusted java.* values plus the Camel holder object itself, so no gadget chain is required. The demonstrated impact is attacker control over the routed Exchange body, headers, and properties; the README notes that variables, exchange id, and exception can also be influenced. Operational flow: an operator calls the HTTP endpoint /exploit/attack on port 8080. The app then publishes a JMS ObjectMessage to the cve queue on the Artemis broker at tcp://artemis:61616 (or tcp://localhost:61616 outside Docker). The victim Camel consumer receives from jms:queue:cve and unmarshals the forged holder before route processing, proving the bypass. Overall, this is a valid exploit PoC with a hardcoded but functional payload, intended to reproduce and demonstrate the vulnerability against affected Apache Camel JMS consumers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary Exchange state-injection vulnerability in Apache Camel JMS components.
A deserialization-filter bypass in Apache Camel JMS-family consumers. A malicious JMS ObjectMessage containing an allow-listed DefaultExchangeHolder can cause arbitrary Camel Exchange state—including body, headers, properties, variables, exchange ID, and exceptions—to be injected without a deserialization gadget chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.