Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-33454

Apache Camel: camel-mail consumers map Camel headers from inbound mail

Technology

Apache Camel

CVSS Score

9.4 / 10.0

Affected Versions

3.0.0 before 4.14.6; 4.15.0 before 4.18.1

Upstream Fix

4.14.6; 4.18.1; 4.19.0

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

MailHeaderFilterStrategy filtered only the outbound direction, so Camel-prefixed MIME headers on mail consumed over IMAP or POP3 reached the exchange unfiltered. Anyone able to send mail to a monitored mailbox could change the behaviour of downstream components such as camel-bean, camel-exec or camel-sql. Rated high by the Camel project. Fixed in 4.14.6, 4.18.1 and 4.19.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.1, you need this patch. Book a discovery call to get covered.