Server-Side Request Forgery (SSRF) in Apache Neethi - CVE-2026-42404
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to access internal network resources.
The vulnerability exists due to improper input validation in the PolicyReference API when fetching remote policy references from user-supplied URIs. A remote attacker can supply a crafted URI to access internal network resources.
Exploitation requires an application to explicitly call the API to retrieve a policy from a remote URI.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-42404
Red Hat Camel for Spring Boot - update to 4.14