TWO high‑severity vulnerabilities in Apache Camel Karavan have been disclosed, exposing open‑source cloud integration environments to potential remote code execution and malicious Kubernetes resource injection. The flaws are tracked as CVE‑2026‑103413 and CVE‑2026‑103412, each rated 8.8 on CVSSv3. The worst‑case impact involves unvalidated Kubernetes resources being applied from a project’s kubernetes[.]yaml, giving an attacker control over container deployments. The report states there is no confirmed exploitation at present, but the risk is significant enough to warrant immediate patching.
Affected versions span multiple release branches. The input validation flaw affects 4.0.0 through 4.22.0, while the path traversal bug affects 3.18.0 through 4.22.0. The advisory recommends upgrading to version 4.22.1 to address both issues. The vulnerabilities arise from improper handling during Kubernetes deployments (accepting arbitrary kubernetes[.]yaml content and failing to restrict resource kinds or pod options) and a path traversal weakness in the project file API that can overwrite classpath files.
Organisations using Camel Karavan should apply the 4.22.1 update promptly and consult the official Apache Camel security advisories for any additional guidance. No exploitation evidence is confirmed in public reports, but the patches are clearly necessary to restore secure operation.