Information Exposure Affecting org.apache.camel:camel-netty-http package, versions [,4.14.8)[4.15.0,4.18.3)[4.19.0,4.21.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.5% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-17892600
  • published8 Jul 2026
  • disclosed6 Jul 2026
  • creditYu Bao

Introduced: 6 Jul 2026

NewCVE-2026-49365  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-netty-http to version 4.14.8, 4.18.3, 4.21.0 or higher.

Overview

org.apache.camel:camel-netty-http is a versatile open-source integration framework based on known Enterprise Integration Patterns.

Affected versions of this package are vulnerable to Information Exposure via the muteException handling in the NettyHttpConfiguration and NettyHttpComponent consumer path. An attacker can obtain a full Java stack trace by sending a request that triggers a route-processing exception on a netty-http endpoint. When muteException is left at its default setting, the consumer writes the exception details back to the client as text/plain instead of suppressing the body. That response can expose internal class names, file paths, hostnames, IP addresses, dependency versions, and other exception text to any client that can reach the endpoint.

CVSS Base Scores

version 4.0
version 3.1