Input validation error in Apache Camel - CVE-2026-33454
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in MailHeaderFilterStrategy when consuming mail messages through camel-mail. A remote attacker can send an email with crafted Camel-prefixed MIME headers to alter downstream route behavior and execute arbitrary code.
Exploitation requires the application to consume email from a monitored mailbox and use downstream components that act on injected Camel headers, such as camel-bean, camel-exec, or camel-sql.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-33454
Red Hat Camel for Spring Boot - update to 4.14