CVE-2026-103413
Received Received - Intake

Improper Input Validation in Apache Camel Karavan

Vulnerability report for CVE-2026-103413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities. This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache Camel Karavan 4.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation issue in Apache Camel Karavan versions 4.0.0 through 4.22.0. When a deployment starts, Karavan unmarshalled a project's kubernetes.yaml file and applied all resources without proper restrictions. This allowed authenticated users to deploy arbitrary Kubernetes resources within the service account's permissions, including pods with dangerous security options like hostNetwork, hostPID, hostIPC, hostPath volumes, privileged containers, and privilege escalation.

Detection Guidance

To detect this vulnerability, check if your Apache Camel Karavan version is between 4.0.0 and 4.22.0. Run: kubectl get deployment -n <namespace> -l app=karavan --output=jsonpath='{.items[*].spec.template.spec.containers[?(@.image)].image}' | grep -E 'camel-karavan:(4\.[0-9]{2}\.[0-9]|4\.2[0-1]\.[0-9])'. Also review Kubernetes resources deployed by Karavan for suspicious configurations like hostNetwork, privileged containers, or hostPath volumes.

Impact Analysis

An attacker with access to Karavan could exploit this to deploy malicious pods or resources on your Kubernetes cluster. This could lead to container escapes, privilege escalation, unauthorized access to host resources, or even full cluster compromise, depending on the service account's permissions. The impact depends on what the compromised service account can do.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements like GDPR (data protection) or HIPAA (health data security). Unrestricted pod deployment may allow attackers to exfiltrate sensitive data or gain control over systems handling regulated information, resulting in legal and financial penalties.

Mitigation Strategies

Upgrade Apache Camel Karavan to version 4.22.1 or later immediately. Apply PodSecurity admission controls to block unsafe pod specifications. Restrict the Karavan service account's RBAC permissions to the minimum required. Review all deployed resources for unauthorized configurations and remove any suspicious ones.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart