Impact
Apache Camel includes an Improper Input Validation flaw in its langchain4j‑tools component. The flaw allows an attacker to inject arbitrary header arguments that bypass declared parameter filtering, potentially altering message routing or the visibility of data within downstream components. This issue could facilitate the modification of requests or responses, leading to unauthorized data access or control flow manipulation.
Affected Systems
The vulnerability affects Apache Camel versions 4.8.0 through 4.18.2 and 4.19.0 through 4.20.0. Users running these releases are at risk until they upgrade to a fixed version such as 4.18.3 or 4.21.0 or any later release that includes the patch for the langchain4j‑tools component.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of <1% and the absence from CISA KEV suggest limited public exploitation at this time. Likely attack vectors involve supplying crafted header values to the Camel route that includes the langchain4j‑tools component; an attacker would need the ability to influence the request or message payload. The risk is primarily tied to the ability to redirect or manipulate message traffic, and while exploitation is currently low, organizations should treat the vulnerability as high priority until it is patched.
OpenCVE Enrichment