LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-40047

apache · camel

Published
CVSS9.1
Severitycritical
WeaknessCWE-88
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the `CamelDoclingCustomArguments` exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected path values that contained a literal `../` sequence. As a result, a Camel route that forwards externally-influenced data into the `

References

← Back to the CVE Tracker

Our coverage of CVE-2026-40047

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-40047.