Input validation error in Apache Camel - CVE-2026-49098
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect Kafka messages to an arbitrary topic.
The vulnerability exists due to improper input validation in the Camel Kafka component header handling when processing HTTP headers in a route that bridges an HTTP consumer to a kafka producer. A remote attacker can send a specially crafted HTTP request with a kafka.OVERRIDE_TOPIC header to redirect Kafka messages to an arbitrary topic.
The issue occurs because non-Camel-prefixed kafka.* exchange header names can pass through the upstream HTTP header filter unmodified.