Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2025-29891
Apache Camel: header injection through HTTP request parameters
Technology
Apache Camel
CVSS Score
4.8 / 10.0
Affected Versions
3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2
Upstream Fix
3.22.4; 4.8.5; 4.10.2
Published
March 12, 2025
OSSeva Coverage
Fixed upstream
Description
The same default header filter weakness as CVE-2025-27636, reached through HTTP request parameters or the request payload, which Camel turns into message headers. Applications exposed to the internet over HTTP could have camel-bean or camel-exec behaviour altered. Rated high by the Camel project. Fixed in 3.22.4, 4.8.5 and 4.10.2.
Is your Apache Camel deployment affected?
If you're running 3.10.0 before 3.22.4; 4.8.0 before 4.8.5; 4.10.0 before 4.10.2, you need this patch. Book a discovery call to get covered.