CVE-2026-33454
Apache Camel: camel-mail consumers map Camel headers from inbound mail
Technology
Apache Camel
CVSS Score
9.4 / 10.0
Affected Versions
3.0.0 before 4.14.6; 4.15.0 before 4.18.1
Upstream Fix
4.14.6; 4.18.1; 4.19.0
Published
April 27, 2026
OSSeva Coverage
Fixed upstream
Description
MailHeaderFilterStrategy filtered only the outbound direction, so Camel-prefixed MIME headers on mail consumed over IMAP or POP3 reached the exchange unfiltered. Anyone able to send mail to a monitored mailbox could change the behaviour of downstream components such as camel-bean, camel-exec or camel-sql. Rated high by the Camel project. Fixed in 4.14.6, 4.18.1 and 4.19.0.
Is your Apache Camel deployment affected?
If you're running 3.0.0 before 4.14.6; 4.15.0 before 4.18.1, you need this patch. Book a discovery call to get covered.