Input validation error in Apache Camel - CVE-2026-49086
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect the re-published message to an arbitrary Dapr Pub/Sub component and topic.
The vulnerability exists due to improper input validation in DaprPubSubConsumer and DaprConfigurationOptionsProxy when processing inbound CloudEvents and republishing messages through a Dapr producer. A remote attacker can publish a specially crafted message to the subscribed topic to redirect the re-published message to an arbitrary Dapr Pub/Sub component and topic.
The issue can bypass the route's intended routing and topic-level access controls in the underlying broker.