Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-59230

Apache Camel: camel-mail MimeMultipart data format copies MIME headers without filtering

Technology

Apache Camel

CVSS Score

6.5 / 10.0

Affected Versions

2.17.0 before 4.14.9; 4.15.0 before 4.18.4; 4.19.0 before 4.22.0

Upstream Fix

4.14.9; 4.18.4; 4.22.0

Published

August 24, 2026

OSSeva Coverage

Fixed upstream

Description

With headersInline enabled, the MimeMultipart data format copied every MIME header of an incoming message onto the Camel message with no header filter strategy, so a sender could set Camel-internal headers. Rated medium by the Camel project. Fixed in 4.14.9, 4.18.4 and 4.22.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 2.17.0 before 4.14.9; 4.15.0 before 4.18.4; 4.19.0 before 4.22.0, you need this patch. Book a discovery call to get covered.