Input validation error in Apache Camel - CVE-2026-46457

 

Input validation error in Apache Camel - CVE-2026-46457

Published: August 24, 2026


Vulnerability identifier: #VU144704
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46457
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject Camel control headers into downstream message processing.

The vulnerability exists due to improper input validation in the camel-nats component when mapping inbound NATS message headers into the Camel Exchange. A remote attacker can publish a specially crafted message with arbitrary headers to inject Camel control headers into downstream message processing.

NATS message headers require NATS 2.2 or later, and injected headers can persist across internal direct, seda, and vm hops.


Affected software

Apache Camel

How to mitigate CVE-2026-46457

Install security update from vendor's website.

Apache Camel - addressed in versions 4.15.0, 4.19.0, 4.21.0

External References

Related Security Bulletins