PT-2026-55918 · Apache · Apache Camel

·

CVE-2026-46588

·

Published

2026-05-15

·

Updated

2026-07-06

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Camel versions prior to 4.14.8 Apache Camel versions 4.15.0 through 4.18.2 Apache Camel versions 4.19.0 through 4.20.0
Description Improper input validation in the CouchDB component allows non-Camel-prefixed Exchange headers to bypass the HeaderFilterStrategy. This can lead to an operation override when processing untrusted input.
Recommendations Upgrade to version 4.14.8. Upgrade to version 4.18.3. Upgrade to version 4.21.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09846
CVE-2026-46588
GHSA-5G68-F6XG-VF2R

Affected Products

Apache Camel