Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-47323

Apache Camel: CXF and Knative endpoints do not filter inbound Camel headers

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

3.18.0 before 4.14.6; 4.15.0 before 4.18.2

Upstream Fix

4.14.6; 4.18.2; 4.19.0

Published

May 19, 2026

OSSeva Coverage

Fixed upstream

Description

The header filter strategies in camel-cxf-rest, camel-cxf-transport and camel-knative-http filtered outbound Camel headers only. An unauthenticated client could send Camel-internal headers such as CamelExecCommandExecutable or CamelFileName to CXF-RS, CXF-SOAP or Knative HTTP endpoints, and a route forwarding to camel-exec or camel-file would act on them, allowing code execution or arbitrary file writes. Rated medium by the Camel project. Fixed in 4.14.6, 4.18.2 and 4.19.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 3.18.0 before 4.14.6; 4.15.0 before 4.18.2, you need this patch. Book a discovery call to get covered.