GHSA-c3f3-cc42-xr9v

Suggest an improvement
Source
https://github.com/advisories/GHSA-c3f3-cc42-xr9v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c3f3-cc42-xr9v/GHSA-c3f3-cc42-xr9v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c3f3-cc42-xr9v
Aliases
Published
2026-02-23T09:31:23Z
Modified
2026-02-25T19:45:41.219244Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
Details

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. 

The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0.

Users are recommended to upgrade to version 4.18.0, which fixes the issue.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-25T18:04:33Z",
    "severity": "CRITICAL",
    "nvd_published_at": "2026-02-23T09:17:00Z",
    "cwe_ids": [
        "CWE-346"
    ]
}
References

Affected packages

Maven / org.apache.camel:camel-keycloak

Package

Name
org.apache.camel:camel-keycloak
View open source insights on deps.dev
Purl
pkg:maven/org.apache.camel/camel-keycloak

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.18.0

Affected versions

4.*
4.15.0
4.16.0
4.17.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c3f3-cc42-xr9v/GHSA-c3f3-cc42-xr9v.json"