CVE-2026-103412
Received Received - Intake

Path Traversal in Apache Camel Karavan

Vulnerability report for CVE-2026-103412, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container. This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache Camel Karavan 3.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Apache Camel Karavan where project file names containing directory traversal sequences like ../ could be used to write files outside the intended project directory during Git commits. An authenticated user could overwrite application configuration or files on the classpath, potentially leading to arbitrary code execution in the Karavan container.

Detection Guidance

Check Apache Camel Karavan versions between 3.18.0 and 4.22.0. Inspect Git commit logs for project files with names containing '../' or similar traversal sequences. Review file writes outside the project directory during Git operations.

Impact Analysis

An attacker with access could overwrite critical files, modify application behavior, or execute malicious code within the Karavan container. This could lead to data breaches, system compromise, or unauthorized access depending on the application's role and permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or data exposure, violating confidentiality requirements in GDPR and HIPAA. Overwriting configuration files might also compromise integrity controls required by these regulations.

Mitigation Strategies

Upgrade Apache Camel Karavan to version 4.22.1 or later immediately. Ensure no unauthorized files exist outside project directories. Validate all user-supplied file names and project IDs for path traversal attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103412. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart