Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-29891

Apache Camel: header injection through HTTP request parameters

Technology

Apache Camel

CVSS Score

4.8 / 10.0

Affected Versions

3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2

Upstream Fix

3.22.4; 4.8.5; 4.10.2

Published

March 12, 2025

OSSeva Coverage

Fixed upstream

Description

The same default header filter weakness as CVE-2025-27636, reached through HTTP request parameters or the request payload, which Camel turns into message headers. Applications exposed to the internet over HTTP could have camel-bean or camel-exec behaviour altered. Rated high by the Camel project. Fixed in 3.22.4, 4.8.5 and 4.10.2.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2, you need this patch. Book a discovery call to get covered.