Remote Code Execution Vulnerability in Apache Camel Products
CVE-2026-40453

Currently unrated

What is CVE-2026-40453?

A vulnerability in Apache Camel allows attackers with access to JMS producers to leverage case-variant internal headers for remote code execution. The issue arises due to inconsistent case filtering among various header filter strategies, enabling manipulation that can lead to arbitrary file writes. Users are advised to upgrade to Apache Camel version 4.20.0 or 4.14.6 / 4.18.2 based on their release stream to mitigate this risk.

Affected Version(s)

Apache Camel CoAP 3.0.0 < 4.14.6

Apache Camel CoAP 4.15.0 < 4.18.2

Apache Camel CoAP 4.19.0 < 4.20.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saroj Khadka
.