GHSA-xfxp-ppx7-cqrp

Suggest an improvement
Source
https://github.com/advisories/GHSA-xfxp-ppx7-cqrp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xfxp-ppx7-cqrp/GHSA-xfxp-ppx7-cqrp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xfxp-ppx7-cqrp
Aliases
  • CVE-2026-6857
Published
2026-04-22T15:31:40Z
Modified
2026-06-02T21:46:44.040243444Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
camel-infinispan Vulnerable to Deserialization of Untrusted Data
Details

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.

Database specific
{
    "github_reviewed_at": "2026-04-29T22:06:53Z",
    "nvd_published_at": "2026-04-22T13:16:22Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-502"
    ]
}
References

Affected packages

Maven / org.apache.camel:camel-infinispan

Package

Name
org.apache.camel:camel-infinispan
View open source insights on deps.dev
Purl
pkg:maven/org.apache.camel/camel-infinispan

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.20.0

Affected versions

2.*
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.15.5
2.15.6
2.16.0
2.16.1
2.16.2
2.16.3
2.16.4
2.16.5
2.17.0
2.17.1
2.17.2
2.17.3
2.17.4
2.17.5
2.17.6
2.17.7
2.18.0
2.18.1
2.18.2
2.18.3
2.18.4
2.18.5
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.19.5
2.20.0
2.20.1
2.20.2
2.20.3
2.20.4
2.21.0
2.21.1
2.21.2
2.21.3
2.21.4
2.21.5
2.22.0
2.22.1
2.22.2
2.22.3
2.22.4
2.22.5
2.23.0
2.23.1
2.23.2
2.23.3
2.23.4
2.24.0
2.24.1
2.24.2
2.24.3
2.25.0
2.25.1
2.25.2
2.25.3
2.25.4
3.*
3.0.0-M1
3.0.0-M2
3.0.0-M3
3.0.0-M4
3.0.0-RC1
3.0.0-RC2
3.0.0-RC3
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.5.0
3.6.0
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.7.5
3.7.6
3.7.7
3.8.0
3.9.0
3.10.0
3.11.0
3.11.1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.12.0
3.13.0
3.14.0
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.14.6
3.14.7
3.14.8
3.14.9
3.14.10
3.15.0
3.16.0
3.17.0
3.18.0
3.18.1
3.18.2
3.18.3
3.18.4
3.18.5
3.18.6
3.18.7
3.18.8
3.19.0
3.20.0
3.20.1
3.20.2
3.20.3
3.20.4
3.20.5
3.20.6
3.20.7
3.20.8
3.20.9
3.21.0
3.21.1
3.21.2
3.21.3
3.21.4
3.21.5
3.22.0
3.22.1
3.22.2
3.22.3
3.22.4
4.*
4.0.0-M1
4.0.0-M2
4.0.0-M3
4.0.0-RC1
4.0.0-RC2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.1.0
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.5.0
4.6.0
4.7.0
4.8.0
4.8.1
4.8.2
4.8.3
4.8.4
4.8.5
4.8.6
4.8.7
4.8.8
4.8.9
4.9.0
4.10.0
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.10.7
4.10.8
4.10.9
4.11.0
4.12.0
4.13.0
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.15.0
4.16.0
4.17.0
4.18.0
4.18.1
4.18.2
4.19.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xfxp-ppx7-cqrp/GHSA-xfxp-ppx7-cqrp.json"