Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-27636

Apache Camel: header injection through the default incoming header filter

Technology

Apache Camel

CVSS Score

5.6 / 10.0

Affected Versions

3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2

Upstream Fix

3.22.4; 4.8.5; 4.10.2

Published

March 9, 2025

OSSeva Coverage

Fixed upstream

Description

Camel's default incoming header filter let an attacker include Camel-specific headers. An attacker able to inject such headers could change what components such as camel-bean, camel-jms or camel-exec do, for example calling a different bean method or sending to a different queue. Rated medium by the Camel project. Fixed in 3.22.4, 4.8.5 and 4.10.2. CVE-2026-40453 later fixed the same pattern in non-HTTP header filter strategies.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2, you need this patch. Book a discovery call to get covered.