StackRadar

CVE-2026-40860

Critical

Advisory

Published 27 Apr 2026In the index since 3 Oct 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.015
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,985 indexed, latest versions
Container images
1
deployed by those charts
Fix available
1 of 1
affected package

Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage

Carried by container images the latest versions of 1 of 17,985 indexed charts deploy, on 1 image.

Affected packageAffected versionsFixed inImages
camel-jmsmaven3.22.44.14.71
OSV records
GHSA-m5vh-3fw5-5wgh

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
sentinelopennms-helm-chartsVerified publisher0.5.01 of 2See more

sentinel opennms-helm-charts 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40860.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.4e1880996623f
camel-jms@3.22.4
4.14.7

Open the chart page →

2,106

Container images carrying it

1 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opennms/sentinel:36.0.4e1880996623f
camel-jms@3.22.4
4.14.7
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.