Improper Input Validation in Apache Camel's Atmosphere Websocket Component
CVE-2026-71300

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 August 2026

What is CVE-2026-71300?

An improper input validation vulnerability exists in Apache Camel's Atmosphere Websocket component, affecting several versions. This issue allows external senders to manipulate message delivery by injecting harmful values into specific headers. When bridging an HTTP consumer into an atmosphere-websocket producer, an attacker can exploit this vulnerability to control which connected WebSocket client receives messages, potentially leading to unauthorized information disclosure and incorrect message routing. To mitigate this risk, users must update to the latest version, specifically version 4.22.0 or higher for general releases, and 4.14.9 or 4.18.4 for LTS, or implement header-stripping measures at the trust boundary.

Affected Version(s)

Apache Camel 4.0.0 < 4.14.9

Apache Camel 4.15.0 < 4.18.4

Apache Camel 4.19.0 < 4.22.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Barak Srour from Apiiro
Andrea Cosentino
.