Input validation error in Apache Camel - CVE-2026-48205
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect DNS queries to an attacker-controlled server and disclose sensitive information about internal hostnames.
The vulnerability exists due to improper input validation in the Camel-DNS producer header handling when processing HTTP requests bridged into a dns: producer. A remote attacker can send a specially crafted request with dns.* or term headers to redirect DNS queries to an attacker-controlled server and disclose sensitive information about internal hostnames.
In affected routes, the HTTP header filter does not block these non-Camel-prefixed header names at the HTTP boundary.