This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 80f84254637c docs: security model - defects in Camel's own resource 
limits are VALID-HARDENING (#26896)
80f84254637c is described below

commit 80f84254637ce838985cb103b407b4e5843a2660
Author: Andrea Cosentino <[email protected]>
AuthorDate: Mon Sep 28 18:36:17 2026 +0200

    docs: security model - defects in Camel's own resource limits are 
VALID-HARDENING (#26896)
    
    The denial-of-service entry under "Out of scope" tells operators to rely on
    component-level options, but did not say how to triage a finding that such 
an
    option fails to enforce its documented value. State that a resource limit
    Camel itself offers (for example maxDecompressedSize on the Zip File and Tar
    File data formats) is defence in depth for a property the framework does not
    claim, so such a defect is a bug fixed as VALID-HARDENING rather than a CVE,
    and extend the VALID-HARDENING row of the dispositions table to match.
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Andrea Cosentino <[email protected]>
---
 .../user-manual/modules/ROOT/pages/security-model.adoc | 18 +++++++++++++-----
 1 file changed, 13 insertions(+), 5 deletions(-)

diff --git a/docs/user-manual/modules/ROOT/pages/security-model.adoc 
b/docs/user-manual/modules/ROOT/pages/security-model.adoc
index 35cb0904133f..7e1c525ca750 100644
--- a/docs/user-manual/modules/ROOT/pages/security-model.adoc
+++ b/docs/user-manual/modules/ROOT/pages/security-model.adoc
@@ -923,7 +923,11 @@ be closed as `not a vulnerability`.
   `circuitBreaker`, `resilience4j`, JVM heap limits, and the relevant
   component-level options. Algorithmic-complexity attacks in third-party
   libraries are reported to the upstream project unless Camel exposes the
-  parser in a way that bypasses the library's own limits.
+  parser in a way that bypasses the library's own limits. A resource limit
+  that Camel itself offers, such as `maxDecompressedSize` on the Zip File and
+  Tar File data formats, is defence in depth for a property the framework
+  does not claim: a defect that stops it enforcing its documented value is a
+  bug, fixed as `VALID-HARDENING` rather than published as a CVE.
 * *A deployer placing `camel-management`, the developer console,
   `camel-jolokia`, JMX or another management surface on a public network.*
   These are management surfaces; they assume a trusted network. The
@@ -1209,16 +1213,20 @@ not provided_), not to close the report ad hoc.
   invariants_, _In-scope vulnerability classes_, _Adversary model_
 
 | `VALID-HARDENING`
-| No claimed property is violated, but a recurring misuse or scanner
-  pattern makes the framework elect to harden the default or add a
-  defence-in-depth check at maintainer discretion. Reported privately;
+| No claimed property is violated, but the framework elects to harden the
+  default or add a defence-in-depth check at maintainer discretion - either
+  because a recurring misuse or scanner pattern warrants it, or because a
+  resource limit Camel itself offers for a property it does not claim (such
+  as `maxDecompressedSize` on the Zip File and Tar File data formats) fails
+  to enforce its documented value. Reported privately;
   usually shipped without a CVE; documented in the upgrade guide. The PMC
   may still publish an advisory when a sibling component's accepted
   finding would otherwise make the change look like a silent fix -
   CVE-2026-56140 (`camel-aws2-sns`) documents an inbound filter added to
   a producer-only component with no reachable injection path, alongside
   CVE-2026-46456 in `camel-aws2-sqs` where the path was reachable.
-| _Known limitations_, _Guidance for component authors and reviewers_
+| _Known limitations_, _Guidance for component authors and reviewers_,
+  _Out of scope_
 
 | `OUT-OF-MODEL: trusted-input`
 | Requires control over an input the model marks trusted (route DSL,

Reply via email to