Input validation error in Apache Camel - CVE-2026-46454

 

Input validation error in Apache Camel - CVE-2026-46454

Published: August 24, 2026


Vulnerability identifier: #VU144707
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46454
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject Camel control headers.

The vulnerability exists due to improper input validation in CometdBinding.populateExchangeFromMessage when processing inbound Bayeux messages. A remote attacker can send a specially crafted CometD message with a malicious ext.CamelHeaders map to inject Camel control headers.

The issue is exposed because no Bayeux SecurityPolicy is installed by default, and the injected headers can persist across internal direct, seda, and vm hops.


Affected software

Apache Camel

How to mitigate CVE-2026-46454

Install security update from vendor's website.

Apache Camel - addressed in versions 4.15.0, 4.19.0, 4.21.0

External References

Related Security Bulletins