Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes.yaml
Summary
| CVE | CVE-2026-103413 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-09 13:17:07 UTC |
| Updated | 2026-10-09 16:33:39 UTC |
| Description | Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities. This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.003900000 probability, percentile 0.310350000 (date 2026-10-10)
Problem Types: CWE-20 | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Camel Karavan | affected 4.0.0 4.22.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| camel.apache.org/security/CVE-2026-103413.html | [email protected] | camel.apache.org | |
| github.com/apache/camel-karavan/commit/a773db372eab9f180110ad6129d58004a... | [email protected] | github.com | |
| www.openwall.com/lists/oss-security/2026/10/09/17 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: MopMonk-AI (en)
CNA: Marat Gubaidullin (en)
CNA: Andrea Cosentino (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-28T00:00:00.000Z | Reported to the Apache Security Team and forwarded to the Apache Camel PMC |
| CNA | 2026-08-28T00:00:00.000Z | Fix committed |
| CNA | 2026-09-29T00:00:00.000Z | Apache Camel Karavan 4.22.1 released |
| CNA | 2026-10-07T00:00:00.000Z | Advisory published |
Solutions
CNA: Upgrade to Apache Camel Karavan 4.22.1. Apache Camel Karavan has no maintenance branches, so 4.22.1 is the only release containing the fix. Operators should also ensure PodSecurity admission is enforced on the namespace Karavan deploys into, and keep the service account's RBAC no wider than Karavan requires.
There are currently no legacy QID mappings associated with this CVE.