Apache Camel camel-pqc contains an unsafe deserialization vulnerability in AwsSecretsManagerKeyLifecycleManager.deserializeMetadata(). The method retrieves persisted KeyMetadata from a configured AWS Secrets Manager secret, Base64-decodes it, and passes it to ObjectInputStream.readObject() without an ObjectInputFilter or class allow-list. Because the result is cast to KeyMetadata only after deserialization returns, side effects implemented by a crafted serialized object's readObject() processing can occur before type validation. A principal able to modify the relevant metadata secret can inject a malicious serialized object that is processed during key-lifecycle operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept exploit for Apache Camel camel-pqc unsafe deserialization, CVE-2026-46590. It is not part of a common exploit framework. The repo contains a minimal web application that exposes a single GET endpoint, /exploit/attack, which demonstrates exploitation against FileBasedKeyLifecycleManager in vulnerable camel-pqc versions (camel.version pinned to 4.18.2 in pom.xml). Structure and purpose: Application.java is the Spring Boot entry point. ExploitController.java contains the main exploit flow: it creates a temporary key directory, writes an attacker-controlled legacy serialized key file named victim-key.key, instantiates FileBasedKeyLifecycleManager on that directory, and calls manager.getKey("victim-key"). Because the vulnerable manager migrates legacy .key files using raw ObjectInputStream.readObject() without an ObjectInputFilter, the malicious object is deserialized before the KeyPair cast fails. Gadget.java builds the CommonsCollections6 gadget chain using commons-collections 3.2.1 and reflection into java.util internals. application.properties configures the app to listen on port 8080. Dockerfile and docker-compose.yml provide a reproducible containerized environment. Main exploit capability: arbitrary command execution during deserialization, provided the attacker can write to the key backend used by FileBasedKeyLifecycleManager. The PoC uses a benign hardcoded payload, /usr/bin/touch /tmp/pwned, and then checks for the existence of /tmp/pwned as proof of execution. The exploit is operational rather than weaponized because the payload is hardcoded and the app is purpose-built for demonstration. Attack path: this is primarily a local/file-based exploit condition against the target application's key storage, wrapped in a web-triggerable demo interface. The attacker-controlled input is the planted legacy .key file; the victim action is a routine getKey() call. The exposed HTTP endpoint is only for triggering the demonstration in the PoC environment, not the underlying vulnerability itself. Notable targeting details: README states affected versions are 4.18.0 before 4.18.3 and 4.19.0 before 4.21.0. It also references related incomplete remediation history (CVE-2026-40048) and a sibling AWS Secrets Manager issue (CVE-2026-43867), but the implemented code specifically targets the file-based manager path.
This repository is a working Java/Spring Boot proof-of-concept for CVE-2026-43867, an unsafe deserialization issue in Apache Camel's camel-pqc AwsSecretsManagerKeyLifecycleManager. The exploit demonstrates that if an attacker can write the AWS Secrets Manager metadata secret used by camel-pqc, they can store a Base64-encoded serialized gadget object that will be deserialized with ObjectInputStream.readObject() and no ObjectInputFilter, leading to code execution before the cast to KeyMetadata occurs. Repository structure is small and focused: Application.java starts the Spring Boot app; ExploitController.java is the main exploit logic and exposes GET /exploit/attack; Gadget.java constructs a CommonsCollections6 gadget chain using commons-collections 3.2.1; application.properties sets the server port; docker-compose.yml launches LocalStack and the app; Dockerfile packages the app with the required JVM option for gadget construction; README.md documents the vulnerability, prerequisites, and reproduction steps. Main exploit capability: the controller first creates or updates the secret pqc/keys/victim-key/metadata in AWS Secrets Manager (here emulated by LocalStack) with crafted JSON containing a malicious Base64 serialized object in the metadata field. It then instantiates AwsSecretsManagerKeyLifecycleManager and calls getKeyMetadata("victim-key"), which causes the vulnerable code path to deserialize attacker-controlled bytes. The gadget executes Runtime.exec with /usr/bin/touch /tmp/pwned, proving code execution. The exploit is operational rather than just a detector because it includes a concrete payload and full trigger path. The exploit uses both web and cloud/network vectors: a local HTTP endpoint triggers the attack flow, while the actual vulnerability target is the AWS Secrets Manager-backed metadata retrieval path in camel-pqc. The PoC is not part of a larger exploit framework; it is a standalone reproducer intended for authorized testing and research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.