Input validation error in Apache Camel - CVE-2026-47323
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or write arbitrary files.
The vulnerability exists due to improper input validation in the CXF and Knative HeaderFilterStrategy implementations when handling HTTP requests to CXF-RS or CXF-SOAP endpoints. A remote attacker can inject Camel-internal headers to execute arbitrary code or write arbitrary files.
Exploitation requires a route that forwards messages from affected endpoints to header-driven components such as camel-exec or camel-file.