PT-2026-41898 · Apache · Camel-Cxf+1

·

CVE-2026-47323

·

Published

2026-05-10

·

Updated

2026-07-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Camel (affected versions not specified)
Description An unauthenticated attacker can perform message header injection due to missing inbound filtering in the CxfRsHeaderFilterStrategy and Knative HeaderFilterStrategy implementations. This allows the injection of Camel-internal headers to override configured values, which can lead to remote code execution or arbitrary file writes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10102
CVE-2026-47323
GHSA-8364-HFQJ-PWM6

Affected Products

Camel-Cxf
Camel-Knative