Input validation error in Apache Camel - CVE-2026-78329

 

Input validation error in Apache Camel - CVE-2026-78329

Published: August 25, 2026


Vulnerability identifier: #VU145150
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78329
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to influence websocket message delivery to an unintended peer.

The vulnerability exists due to improper input validation in the Camel Undertow endpoint header filtering logic when processing inbound and outbound undertow headers on endpoint-configured routes. A remote attacker can send specially crafted headers with the legacy websocket. prefix to influence websocket message delivery to an unintended peer.

Only endpoint-configured routes that rely on the default undertow header filter strategy are affected; Rest DSL consumers were not affected.


Affected software

Apache Camel

How to mitigate CVE-2026-78329

Install security update from vendor's website.

Apache Camel - addressed in versions 4.14.9, 4.18.4, 4.22.0

External References

Related Security Bulletins