CVE-2026-49365 is an information-disclosure vulnerability in the Apache Camel camel-netty-http HTTP server consumer. Its muteException option defaulted to false due to an uninitialized primitive boolean, unlike other Camel HTTP server components that default the option to true. Consequently, an exception raised during route processing causes the HTTP response to contain the complete Java Throwable stack trace as plain text rather than an empty response body. Affected versions are Apache Camel 4.0.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-49365, an information disclosure flaw in Apache Camel's camel-netty-http and camel-undertow components. The issue is not remote code execution; it demonstrates CWE-209 behavior where uncaught exceptions are returned to HTTP clients as full Java stack traces because muteException defaults to false in affected versions. Repository structure is small and purpose-built: Application.java is the Spring Boot entry point; VictimRoutes.java defines three Camel HTTP consumer routes on ports 8888, 8889, and 8890; FailingProcessor.java throws a crafted IllegalStateException containing representative sensitive data; ExploitController.java exposes /exploit/attack on port 8080 and programmatically sends GET requests to each route, then formats the responses to show which endpoints leak stack traces. application.properties sets the app port and Camel runtime behavior. Dockerfile and docker-compose.yml package the reproducer as a single containerized service. Main exploit capability: trigger an HTTP 500 on vulnerable Camel netty-http and undertow endpoints and retrieve the full stack trace in the response body. The PoC proves leakage by checking for a marker string tied to a simulated internal JDBC URL. It also includes a safe comparison endpoint with muteException=true to show the patched/mitigated behavior of an empty response body. Notable fingerprintable targets and observables include the local attack endpoint /exploit/attack on port 8080, vulnerable listeners on 8888 and 8890, the muted comparison listener on 8889, and leaked internal values such as prod-db.internal, 10.20.30.40, jdbc:postgresql://prod-db.internal:5432/inventory, and the vault secret identifier inventory/db. Overall, this is a legitimate operational PoC for information disclosure testing against affected Apache Camel HTTP consumer configurations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.