Skip to content
Rota Nacional

Cyber ·

CVE-2026-103412: path traversal in Apache Camel Karavan via project file name

Advisory dated October 9, 2026: the project file API used a supplied name without restriction as a path segment when writing to Git. CVSS 8.8; versions 3.18.0 up to before 4.22.1.

According to the advisory published by Andrea Cosentino on October 9, 2026 on the oss-sec list, Apache Camel Karavan allows path traversal. The project file API accepted a file name and used it unchanged as a path segment when writing the project to the Git working copy, which allows writing outside the intended directory. The flaw affects versions 3.18.0 up to before 4.22.1 and has a CVSS 3.1 score of 8.8 (high), with network vector, low complexity, low privileges and high impact on confidentiality, integrity and availability.

The original text is a machine translation of the feed. To verify, consult identifier CVE-2026-103412 on the oss-sec list and the official Apache Camel Karavan project documentation, confirming the installed version and the fix in 4.22.1 or later. The advisory as described gives no exploitation details beyond this description.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free