Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-49365 — PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0. | Kitploit
Tools/GitHubGitHub/oscerd/cve-2026-49365
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingLearning & Education
GitHuboscerd/cve-2026-49365

CVE-2026-49365

PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.

View Repository
28 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-49365 — camel-netty-http / camel-undertow muteException Stack-Trace Disclosure

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

RuntimeDirectoryStackComponents shown
Camel Spring Bootcamel-spring-boot/Spring Boot 3.2.0 + camel-spring-boot 4.18.2netty-http and undertow
Camel Quarkuscamel-quarkus/Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0)netty-http (no camel-quarkus-undertow extension)

Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect: the muteException option ships with a default of false in camel-netty-http (and camel-undertow), so on any processing error the full Java stack trace is returned to the HTTP client — leaking internal backend hostnames, database URLs, credential/vault hints, library versions and source locations (CWE-209). jetty/servlet and platform-http already default it to true.

Each subdirectory is a self-contained project with its own Dockerfile, docker-compose.yml, and README. In short, for either:

root@kitploit:~
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

Vulnerability Summary

Advisory: https://camel.apache.org/security/CVE-2026-49365.html

Disclaimer

These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.

Download Tool
PropertyValue
Componentscamel-netty-http, camel-undertow
CWECWE-209 (Generation of Error Message Containing Sensitive Information)
ImpactFull Java stack trace returned to an unauthenticated HTTP client on any processing error
Affected VersionsFrom 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0
Fixed Versions4.14.8, 4.18.3, 4.21.0
JIRACAMEL-23651 (PR apache/camel#23913)
CreditYu Bao (PayPal)