Apache disclosed four vulnerabilities in Apache Camel affecting message handling and request protection across multiple components. The most severe issues, CVE-2026-33453 and CVE-2026-33454, allow attackers to inject Camel internal headers through untrusted inputs that are copied into the Exchange without proper inbound filtering. In camel-coap, a single unauthenticated UDP packet can place arbitrary query parameters into Exchange headers, enabling pre-authentication remote code execution when routes forward data to header-sensitive components such as camel-exec, camel-sql, camel-bean, camel-file, or template processors. In camel-mail, emails received over IMAP or POP3 can carry crafted MIME headers with the Camel prefix that reach downstream components and similarly influence execution, making remote code execution possible in vulnerable deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed an important-severity vulnerability caused by an incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategy implementations including camel-jms, camel-sjms, camel-coap, and camel-google-pubsub. The bug allows case-variant internal header injection that can lead to remote code execution or arbitrary file write in affected routes.
Apache disclosed a moderate-severity authentication bypass in camel-platform-http-main affecting non-root context paths when the authentication path is not explicitly set. The flaw can expose protected routes and management endpoints, and Apache recommended upgrading affected 4.14.x and 4.18.x releases.
Apache disclosed an important-severity flaw in camel-mail where inbound MIME headers are not filtered, allowing attackers to inject Camel-specific headers via email and potentially trigger downstream remote code execution. Apache said affected versions include 3.0.0 before 4.14.6 and 4.15.0 before 4.18.1, and credited Hyunwoo Kim.
Apache disclosed a high-severity vulnerability in the camel-coap component that allows CoAP URI query parameters to be injected into Camel Exchange headers, enabling single-packet pre-authentication RCE in vulnerable routes. The issue affects camel-coap 4.14.0 through 4.14.5, 4.18.0 before 4.18.1, and 4.19.0, and was credited to Hyunwoo Kim.
Apache Camel resolved a camel-coap issue in JIRA where CoAP query parameters were mapped to Camel Exchange headers without a HeaderFilterStrategy. The fix was released in versions 4.14.6 and 4.18.1 and tracked through coordinated pull requests across supported branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceissues.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.