CVE-2025-27636
Apache Camel: header injection through the default incoming header filter
Technology
Apache Camel
CVSS Score
5.6 / 10.0
Affected Versions
3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2
Upstream Fix
3.22.4; 4.8.5; 4.10.2
Published
March 9, 2025
OSSeva Coverage
Fixed upstream
Description
Camel's default incoming header filter let an attacker include Camel-specific headers. An attacker able to inject such headers could change what components such as camel-bean, camel-jms or camel-exec do, for example calling a different bean method or sending to a different queue. Rated medium by the Camel project. Fixed in 3.22.4, 4.8.5 and 4.10.2. CVE-2026-40453 later fixed the same pattern in non-HTTP header filter strategies.
Is your Apache Camel deployment affected?
If you're running 3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2, you need this patch. Book a discovery call to get covered.