Improper Input Validation in Apache Camel Karavan
CVE-2026-103413
8.8HIGH
What is CVE-2026-103413?
An improper input validation vulnerability exists in Apache Camel Karavan, allowing authenticated users to deploy arbitrary Kubernetes resources without proper restrictions. When deploying, the application fails to validate the contents of the kubernetes.yaml file adequately, allowing for potential exploitation via sensitive pod settings such as hostNetwork, hostPID, hostIPC, and hostPath volumes. These issues pose significant security risks as attackers can gain escalated privileges within the Kubernetes cluster by manipulating these deployment resources. Users are strongly advised to upgrade to version 4.22.1, which addresses these vulnerabilities.
Affected Version(s)
Apache Camel Karavan 4.0.0 < 4.22.1