RHSA-2025:18028HighCVSS 7.5

Red Hat Security Advisory: Red Hat Build of Apache Camel 4.10.7 for Spring Boot release.

Published
October 14, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-4949 — org.eclipse.jgit: XXE vulnerability in Eclipse JGit CVE-2025-41248 — org.springframework.security/spring-security-core: Spring Security authorization bypass CVE-2025-41249 — org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability CVE-2025-58056 — netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions CVE-2025-59952 — io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution

🎯 Affected products1

  • Red Hat build of Apache Camel 4.10.7 for Spring Boot 3.4.10

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, enforce strict RFC compliance on all front-end proxies and load balancers so that lone LF characters in chunk extensions are rejected or normalized before being forwarded. Additionally, configure input validation at the application or proxy layer to block malformed chunked requests, ensuring consistent parsing across all components in the request path.

🔗 References (8)