PT-2026-35384 · Apache · Camel-Mail

·

CVE-2026-33454

·

Published

2026-04-27

·

Updated

2026-07-11

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Apache Camel versions prior to 4.19.0
Description A flaw in the Camel-Mail component allows an attacker to perform message header injection by sending a specially crafted email to a mailbox monitored by a Camel application. Due to a missing inbound filter in the MailHeaderFilterStrategy, malicious headers are not properly filtered, which can alter the behavior of downstream components. This issue involves the setOutFilterStartsWith() function and deficiencies in the deserialization mechanism, potentially leading to remote code execution (RCE), where an attacker can execute arbitrary code on the system.
Recommendations Update to version 4.19.0 or the latest supported LTS release.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09302
CVE-2026-33454
GHSA-2VQF-X7G4-7C2G

Affected Products

Camel-Mail