Improper Neutralization of HTTP Headers for Scripting Syntax in Apache Camel - CVE-2025-27636
Published: March 10, 2025 / Updated: April 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper input validation when processing HTTP requests, as filters are configured to only block headers starting with "Camel", "camel", or "org.apache.camel". A remote non-authenticated attacker can send a specially crafted HTTP request with altered casing of letters in headers that will be accepted by the application.
Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.
Affected software
Oracle Banking Origination
Oracle Banking Virtual Account Management
Red Hat Camel for Spring Boot
How to mitigate CVE-2025-27636
Red Hat Camel for Spring Boot - addressed in versions 4.8, 4.8.5
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Header injection vulnerability in Apache Camel
- Improper Neutralization of HTTP Headers for Scripting Syntax in Red Hat Camel for Spring Boot 4
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.8
- Multiple vulnerabilities in Oracle Banking Origination
- Multiple vulnerabilities in Oracle Banking Virtual Account Management