Description
Improper Input Validation vulnerability in Apache Camel.

This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.

Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
Published: 2026-07-06
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Camel's CouchDB component contains an improper input‑validation flaw that allows non‑Camel‑prefixed Exchange headers to bypass the HeaderFilterStrategy and override CouchDB operations via untrusted input. This flaw means an attacker who can influence headers in a Camel route can manipulate the commands sent to CouchDB, threatening the integrity of stored data. The weakness is categorized as CWE-20.

Affected Systems

The vulnerability affects Apache Camel version 4.14.7 and earlier, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0 when the CouchDB component is used. Versions 4.14.8, 4.18.3, 4.21.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity risk. The EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve supplying malicious headers to a Camel route that interacts with CouchDB. An attacker would need to have nominal access to the Camel instance and ability to set headers, which could allow operation override against the underlying database.

Generated by OpenCVE AI on August 1, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Camel to a fixed release—4.14.8, 4.18.3, 4.21.0, or later.
  • Restrict network access to Camel routes that communicate with CouchDB to trusted networks or authenticated clients.
  • Implement input validation or sanitization for any data that will be passed into the CouchDB component, ensuring headers conform to expected formats and preventing bypass of the HeaderFilterStrategy.

Generated by OpenCVE AI on August 1, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache camel
Vendors & Products Apache
Apache camel

Mon, 06 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
Title Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-06T21:31:57.875Z

Reserved: 2026-05-15T08:57:46.627Z

Link: CVE-2026-46588

cve-icon Vulnrichment

Updated: 2026-07-06T21:31:57.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-06T11:16:28.777

Modified: 2026-07-08T14:38:22.180

Link: CVE-2026-46588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T18:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation