Skip to content

[GHSA-v3vg-332r-mw99] Camel-PQC: split affected range to match the upstream advisory - #9017

Open
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9017from
pacocartones:pacocartones-GHSA-v3vg-332r-mw99
Open

[GHSA-v3vg-332r-mw99] Camel-PQC: split affected range to match the upstream advisory#9017
pacocartones wants to merge 1 commit into
github:pacocartones/advisory-improvement-9017from
pacocartones:pacocartones-GHSA-v3vg-332r-mw99

Conversation

@pacocartones

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The advisory records a single range, 0 -> 4.18.2, but the upstream advisory it already references states two:

Versions affected: From 4.19.0 before 4.20.0, from 4.18.0 before 4.18.2.
Versions fixed: 4.18.2 and 4.20.0

https://camel.apache.org/security/CVE-2026-40048.html

org.apache.camel:camel-pqc 4.19.0 and 4.20.0 are both published on Maven Central, so as recorded the advisory has two problems at once: 4.19.0 is affected but falls outside the range, and 4.13.0 through 4.17.0 are flagged without being affected.

Splitting into 4.18.0 -> 4.18.2 and 4.19.0 -> 4.20.0 matches the sibling advisories from the same Camel batch, which map the same sentence shape to two affected entries — see GHSA-8364-hfqj-pwm6 (3.18.0 -> 4.14.6 and 4.15.0 -> 4.18.2) and GHSA-2vqf-x7g4-7c2g.

Nothing else is touched: no package, severity, CWE, CVSS or description changes.

@github-actions
github-actions Bot changed the base branch from main to pacocartones/advisory-improvement-9017 August 7, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant