Impact
Apache Camel’s langchain4j‑tools component contains an improper input validation flaw that allows an attacker to inject arbitrary HTTP header arguments that bypass the component’s declared parameter filtering. Because headers control message routing and data visibility within downstream Camel components, an attacker who can supply crafted headers can alter routing logic or expose hidden data, resulting in unauthorized control of message flow or data leakage.
Affected Systems
Vulnerable releases are all Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0. The issue resides in the langchain4j‑tools component, and any application that uses those Camel releases and employs the component is susceptible until a patched release such as 4.18.3 or21.0 is deployed.
Risk and Exploitability
The CVSS score of 7.3 classifies the vulnerability as high severity, yet the EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that it is currently unlikely to be exploited in the wild. The most probable attack scenario involves an attacker who can influence inbound requests or message payloads to add malicious headers; such an attacker could then redirect or manipulate the Camel route, potentially providing unauthorized data access or controlling message flow. Organizations should regard the vulnerability as high risk until the vendor’s patch is applied.
OpenCVE Enrichment