According to the advisory published by Andrea Cosentino on October 9, 2026 on the oss-sec mailing list, in Apache Camel Karavan a deployment deserializes a project's kubernetes.yaml file and applies to the cluster every resource it contains. The input validation flaw does not restrict resource types and does not reject security-sensitive pod settings. The reported severity is CVSS 3.1 of 8.8, rated high, with network vector, low complexity, low privileges, no user interaction and high impact on confidentiality, integrity and availability. Affected versions range from 4.0.0 before 4.22.1. This item is a security advisory and contains no usage tutorial. To verify, consult the original text on the oss-sec list, whose reference appears in the Radar record, and confirm the Karavan version installed in your environment. Rota Nacional does not fix or replace Karavan, and placeholder-based protection of personal data does not address Kubernetes manifest validation.
Cyber ·
CVE-2026-103413: Apache Camel Karavan applies unvalidated Kubernetes resources
Security advisory with CVSS 8.8 for Apache Camel Karavan from version 4.0.0 before 4.22.1, which applies to the cluster every resource in kubernetes.yaml without checking resource types or rejecting sensitive pod settings.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.