CVE-2026-47323
Apache Camel: CXF and Knative endpoints do not filter inbound Camel headers
Technology
Apache Camel
CVSS Score
9.8 / 10.0
Affected Versions
3.18.0 before 4.14.6; 4.15.0 before 4.18.2
Upstream Fix
4.14.6; 4.18.2; 4.19.0
Published
May 19, 2026
OSSeva Coverage
Fixed upstream
Description
The header filter strategies in camel-cxf-rest, camel-cxf-transport and camel-knative-http filtered outbound Camel headers only. An unauthenticated client could send Camel-internal headers such as CamelExecCommandExecutable or CamelFileName to CXF-RS, CXF-SOAP or Knative HTTP endpoints, and a route forwarding to camel-exec or camel-file would act on them, allowing code execution or arbitrary file writes. Rated medium by the Camel project. Fixed in 4.14.6, 4.18.2 and 4.19.0.
Is your Apache Camel deployment affected?
If you're running 3.18.0 before 4.14.6; 4.15.0 before 4.18.2, you need this patch. Book a discovery call to get covered.