RHSA-2026:3890HighCVSS 9.6
Red Hat Security Advisory: Red Hat Build of Apache Camel 4.14.4 for Spring Boot release.
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-12543 — undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-27727 — com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects CVE-2026-27830 — c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:3890
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2408784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442908
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3890.json