- Issued:
- 2026-09-03
- Updated:
- 2026-09-03
RHSA-2026:63302 - Security Advisory
Synopsis
Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.SP1)
Type/Severity
Security Advisory: Important
Topic
An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.SP1).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.Red Hat Product Security has rated this update as having a security impact of Important.
Description
An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.SP1).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:
- httpclient5-cache: Apache HttpComponents Client: Denial of Service due to connection leak [rhboac-camel-quarkus-3] ()
- httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak [rhboac-camel-quarkus-3] ()
- camel-quarkus-support-httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak [rhboac-camel-quarkus-3] ()
- netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [rhboac-camel-quarkus-3] (CVE-2026-62243)
- camel-quarkus-support-httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification [rhboac-camel-quarkus-3] (CVE-2026-71290)
- quarkus-apache-httpclient: Apache HttpComponents Client: Denial of Service due to connection leak [rhboac-camel-quarkus-3] (CVE-2026-64607)
- proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching [rhboac-camel-quarkus-3] (CVE-2026-66257)
- proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation [rhboac-camel-quarkus-3] (CVE-2026-66273)
- mongodb-driver-legacy: MongoDB Driver: Credential disclosure via cleartext logging during client initialization [rhboac-camel-quarkus-3] ()
- mongodb-driver-core: MongoDB Driver: Credential disclosure via cleartext logging during client initialization [rhboac-camel-quarkus-3] (CVE-2026-18710)
- resteasy-core: RESTeasy SourceProvider remote unauthenticated file read [rhboac-camel-quarkus-3] (CVE-2026-17615)
- proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting [rhboac-camel-quarkus-3] (CVE-2026-66274)
- quarkus-qute: Quarkus:Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine [rhboac-camel-quarkus-3] ()
- camel-quarkus-qute-component: Quarkus:Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine [rhboac-camel-quarkus-3] ()
- camel-quarkus-qute: Quarkus:Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine [rhboac-camel-quarkus-3] (CVE-2026-12894)
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).
Affected Products
- Red Hat Build of Apache Camel 1 x86_64
Fixes
- BZ - 2507635 - CVE-2026-17615 resteasy-core: RESTeasy SourceProvider remote unauthenticated file read
- BZ - 2509736 - CVE-2026-64607 org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak
- BZ - 2511322 - CVE-2026-66273 org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation
- BZ - 2511326 - CVE-2026-66257 qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
- BZ - 2511337 - CVE-2026-66274 org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- BZ - 2514394 - CVE-2026-71290 org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification
- BZ - 2514429 - CVE-2026-18710 org.mongodb/mongodb-driver: MongoDB Driver: Credential disclosure via cleartext logging during client initialization
- BZ - 2521309 - CVE-2026-62243 io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
CVEs
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.