Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-49365 — PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0. | Kitploit
Ferramentas/GitHubGitHub/oscerd/cve-2026-49365
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingLearning & Education
GitHuboscerd/cve-2026-49365

CVE-2026-49365

PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.

Ver Repositório
há 28 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-49365 — camel-netty-http / camel-undertow muteException Stack-Trace Disclosure

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

RuntimeDirectoryStackComponents shown
Camel Spring Bootcamel-spring-boot/Spring Boot 3.2.0 + camel-spring-boot 4.18.2netty-http and undertow
Camel Quarkuscamel-quarkus/Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0)netty-http (no camel-quarkus-undertow extension)

Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect: the muteException option ships with a default of false in camel-netty-http (and camel-undertow), so on any processing error the full Java stack trace is returned to the HTTP client — leaking internal backend hostnames, database URLs, credential/vault hints, library versions and source locations (CWE-209). jetty/servlet and platform-http already default it to true.

Each subdirectory is a self-contained project with its own Dockerfile, docker-compose.yml, and README. In short, for either:

root@kitploit:~
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

Vulnerability Summary

Advisory: https://camel.apache.org/security/CVE-2026-49365.html

Disclaimer

These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.

Baixar ferramenta
PropertyValue
Componentscamel-netty-http, camel-undertow
CWECWE-209 (Generation of Error Message Containing Sensitive Information)
ImpactFull Java stack trace returned to an unauthenticated HTTP client on any processing error
Affected VersionsFrom 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0
Fixed Versions4.14.8, 4.18.3, 4.21.0
JIRACAMEL-23651 (PR apache/camel#23913)
CreditYu Bao (PayPal)