🛡️ CVE-2026-40047 — camel

🔴 CVSS 9.1 — Critical ✅ No Known Exploit CWE-88 NVD
9.1
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.

The camel-docling component invokes the external docling command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the CamelDoclingCustomArguments exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected path values that contained a literal ../ sequence. As a result, a Camel route that forwards externally-influenced data into the CamelDoclingCustomArguments header (or into the path-bearing headers used to build the invocation) could cause the producer to pass unrecognized or unintended docling CLI flags to the subprocess, and could supply path-like argument values that resolved outside the intended directory through traversal sequences not caught by the literal ../ check. Because Camel itself builds the docling invocation from these values, the component is responsible for constraining them, and the weak validation allowed CLI-argument injection and directory traversal in the arguments passed to the external tool. The invocation uses the list-based form of ProcessBuilder, so a shell does not interpret the argument values; OS command injection through shell metacharacters was not possible, and the metacharacter rejection added by the fix is defense-in-depth.

This issue affects Apache Camel: from 4.15.0 before 4.18.3.

Users are recommended to upgrade to a release that contains the CAMEL-23212 fix. On the mainline the fix is included from Apache Camel 4.19.0 (and later releases such as 4.20.0). For users on the 4.18.x LTS releases stream, upgrade to 4.18.3. The fix replaces the denylist with a strict allowlist of recognized docling CLI flags (rejecting any unrecognized flag, and rejecting producer-managed flags such as the output-directory flags), defensively rejects shell metacharacters in argument values, and normalizes path-like values with Path.normalize() before validating them so that traversal sequences which bypass a literal ../ check are detected. As defence in depth, route authors should avoid mapping untrusted message content into the CamelDoclingCustomArguments header and the path-bearing headers, and should strip Camel-internal headers from messages that arrive from untrusted producers.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability none.

Weakness class

CVE-2026-40047 is classified as CWE-88: Argument Injection. Input is passed into a command line without separating data from options, letting an attacker introduce extra arguments.

Affected software

CVE-2026-40047 is recorded against 1 package.

  • camel (from 4.15.0 up to 4.18.3)

Timeline and source

Published on 6 July 2026 and last revised on 8 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

camel.apache.org
www.openwall.com

Details

Severity CRITICAL
CVSS Score 9.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE CWE-88
Public Exploit ✅ No
Source NVD
Published 2026-07-06
Updated 2026-08-11
Modified 2026-07-08
Fix URL N/A

Affected Packages

Software From version Fixed in
camel 4.15.0 4.18.3

Similar Threats

Exploit Protection

Are you running camel?

CVE-2026-40047 carries CVSS 9.1 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-40047 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.