← Vulnerability feed

Vulnerability record · CVE-2020-11973 · published 14 May 2020

CVE-2020-11973: Apache camel deserialization of untrusted data vulnerability

Apache · Camel

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

9.8 CVSS 3.1 Critical EPSS 6.6% · top 6.4% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11973 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed10.0CVE-2026-33453Apache camel mass assignment vulnerabilityImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's cam…EPSS 7.2%10.0CVE-2013-4316Apache struts improper access control vulnerabilityApache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.EPSS 8.4%9.9CVE-2026-46854Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Target Management). Supported versions …EPSS 0.43%9.9CVE-2026-46855Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions th…EPSS 0.43%9.9CVE-2026-46852Oracle enterprise manager base platform improper privilege management vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions th…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2020-11973), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.