Input validation error in Apache Camel - CVE-2026-40453
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code or write arbitrary files.
The vulnerability exists due to improper input validation in non-HTTP HeaderFilterStrategy implementations when processing broker messages with case-variant Camel internal headers. A remote user can inject crafted headers to execute arbitrary code or write arbitrary files.
Exploitation requires producer access to a JMS or equivalent broker consumed by a Camel route, and affects routes that forward messages to header-driven components such as camel-exec or camel-file.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-40453
Red Hat Camel for Spring Boot - update to 4.14