Details:
An update for Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [rhboac-camel-quarkus-3] (CVE-2026-59899) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [rhboac-camel-quarkus-3] (CVE-2026-56819) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [rhboac-camel-quarkus-3] (CVE-2026-56746) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [rhboac-camel-quarkus-3] (CVE-2026-56745) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [rhboac-camel-quarkus-3] (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [rhboac-camel-quarkus-3] (CVE-2026-55831) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation [rhboac-camel-quarkus-3] (CVE-2026-15076) * smallrye-mutiny-vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [rhboac-camel-quarkus-3] (CVE-2026-15075) * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [rhboac-camel-quarkus-3] (CVE-2026-15075) * httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks [rhboac-camel-quarkus-3] (CVE-2026-54428) * camel-vertx-http: Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data [rhboac-camel-quarkus-3] (CVE-2026-40859) * camel-mail: Apache Camel Mail Component: Credential...
Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:HI:LA:N8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N