PT-2025-10464 · Apache · Apache Camel

·

CVE-2025-27636

·

Published

2025-03-09

·

Updated

2026-08-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Camel versions 4.10.0 through 4.10.1 Apache Camel versions 4.8.0 through 4.8.4 Apache Camel versions 3.10.0 through 3.22.3
Description A bypass and injection issue exists in the default incoming header filter of Apache Camel due to case-sensitive filtering. The mechanism only blocks headers starting with "Camel", "camel", or "org.apache.camel.", allowing attackers to bypass these filters using mixed-case headers (e.g., cAmel) or HTTP request parameters. This can lead to remote code execution (RCE) by altering the behavior of specific components. For example, in the camel-bean component, an attacker can invoke methods other than those intended by the application. In the camel-jms component, malicious headers can redirect messages to different queues on the same broker. The camel-exec component is also susceptible to command overwriting. This issue is particularly critical for applications directly exposed to the internet via HTTP components such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http. Thousands of scans and attack attempts have been recorded in the wild, especially within cloud-native environments like Kubernetes clusters.
Recommendations Upgrade Apache Camel version 4.10.x LTS to 4.10.2. Upgrade Apache Camel version 4.8.x LTS to 4.8.5. Upgrade Apache Camel version 3.x to 3.22.4. As a temporary workaround, use the removeHeaders EIP to filter out headers that do not strictly start with "Camel", "camel", or "org.apache.camel.".

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02723
BDU:2025-03703
CVE-2025-27636
GHSA-2C2H-2855-MF97
GHSA-96V5-C2H5-56HM
GHSA-VQ4P-PCHP-6G6V

Affected Products

Apache Camel