- What: Security update for Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33
- Impact: Improves security and stability for developers
Red Hat Product Errata RHSA-2026:48118 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:48118 - Security Advisory Overview Synopsis Important: Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3) Type/Severity Security Advisory: Important Topic An update for Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. Red Hat Product Security has rated this update as having a security impact of Important. Description An update for Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: netty-codec- http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [rhboac-camel-quarkus-3] (CVE-2026-59899) netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [rhboac-camel-quarkus-3] (CVE-2026-56819) netty-codec- http: Netty: Security control bypass allows unauthorized requests via null origin header [rhboac-camel-quarkus-3] (CVE-2026-56746) netty-codec- http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [rhboac-camel-quarkus-3] (CVE-2026-56745) netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [rhboac-camel-quarkus-3] (CVE-2026-55851) netty-codec- http: Netty: Denial of Service via SPDY SETTINGS frame processing [rhboac-camel-quarkus-3] (CVE-2026-55831) vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation [rhboac-camel-quarkus-3] (CVE-2026-15076) smallrye-mutiny-vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [rhboac-camel-quarkus-3] (CVE-2026-15075) vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [rhboac-camel-quarkus-3] (CVE-2026-15075) httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks [rhboac-camel-quarkus-3] (CVE-2026-54428) camel-vertx- http: Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data [rhboac-camel-quarkus-3] (CVE-2026-40859) camel-mail: Apache Camel Mail Component: Credential exposure and information disclosure via improper input validation of mail headers [rhboac-camel-quarkus-3] (CVE-2026-46584) camel-cxf-common: Apache Camel CXF SOAP: Remote attacker can execute unintended operations via header manipulation [rhboac-camel-quarkus-3] (CVE-2026-46592) camel-vertx-websocket: Apache Camel Vertx Websocket: Server-Side Request Forgery and sensitive data exposure [rhboac-camel-quarkus-3] (CVE-2026-46726) httpcore: Apache HttpComponents Core: Denial of Service via excessive HTTP headers [rhboac-camel-quarkus-3] (CVE-2026-54399) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Affected Products Red Hat Build of Apache Camel 1 x86_64 Fixes BZ - 2496101 - CVE-2026-54399 org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers BZ - 2496106 - CVE-2026-54428 org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks BZ - 2497283 - CVE-2026-40859 org.apache.camel/camel-vertx-http: Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data BZ - 2497287 - CVE-2026-46726 camel-vertx-websocket: Apache Camel Vertx Websocket: Server-Side Request Forgery and sensitive data exposure BZ - 2497288 - CVE-2026-46584 org.apache.camel/camel-mail: Apache Camel Mail Component: Credential exposure and information disclosure via improper input validation of mail headers BZ - 2497295 - CVE-2026-46592 org.apache.camel/camel-cxf: Apache Camel CXF SOAP: Remote attacker can execute unintended operations via header manipulation BZ - 2499914 - CVE-2026-15076 io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation BZ - 2499919 - CVE-2026-15075 vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects BZ - 2503103 - CVE-2026-55831 io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing BZ - 2505422 - CVE-2026-56746 io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header BZ - 2505698 - CVE-2026-55851 io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message BZ - 2505911 - CVE-2026-56745 netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec BZ - 2505980 - CVE-2026-56819 io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak BZ - 2507482 - CVE-2026-59899 io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) CVEs CVE-2026-15075 CVE-2026-15076 CVE-2026-40859 CVE-2026-46584 CVE-2026-46592 CVE-2026-46726 CVE-2026-54399 CVE-2026-54428 CVE-2026-55831 CVE-2026-55851 CVE-2026-56745 CVE-2026-56746 CVE-2026-56819 CVE-2026-59899 References https://access.redhat.com/security/updates/classification/#important The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .