PT-2026-35384 · Apache · Camel-Mail
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Camel versions prior to 4.19.0
Description
A flaw in the Camel-Mail component allows an attacker to perform message header injection by sending a specially crafted email to a mailbox monitored by a Camel application. Due to a missing inbound filter in the
MailHeaderFilterStrategy, malicious headers are not properly filtered, which can alter the behavior of downstream components. This issue involves the setOutFilterStartsWith() function and deficiencies in the deserialization mechanism, potentially leading to remote code execution (RCE), where an attacker can execute arbitrary code on the system.Recommendations
Update to version 4.19.0 or the latest supported LTS release.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Camel-Mail