CVE-2026-33453 is an improperly controlled modification of dynamically determined object attributes vulnerability in Apache Camel's camel-coap component. Incoming CoAP URI query parameters are copied into Camel Exchange message headers without a HeaderFilterStrategy. An unauthenticated sender can therefore supply Camel internal headers that influence downstream header-sensitive producers. When a CoAP consumer route forwards the exchange to camel-exec, attacker-controlled executable and argument headers can override endpoint command settings and cause operating-system command execution in the Camel process context. Producer output can be returned in the CoAP response, enabling an interactive command-execution channel. Affected releases include Apache Camel 4.14.0 through 4.14.5 and releases from 4.15.0 before 4.18.1. Fixed releases include 4.14.6, 4.18.1, and 4.19.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact Java/Spring Boot exploit reproducer for CVE-2026-33453 in Apache Camel's camel-coap component. It is not part of a larger exploit framework. The project contains 7 files total, with Java source under src/main/java, Maven build metadata in pom.xml, and runtime configuration in application.properties. Structure and purpose: - Application.java is the Spring Boot entry point. - CoapExecRoute.java defines the vulnerable Camel route: from("coap://0.0.0.0:5683/run") -> to("exec:echo?args=hello") -> convertBodyTo(String.class). This is the victim path demonstrating how untrusted CoAP query parameters become Camel headers and influence a downstream header-sensitive producer. - ExploitController.java is a bundled attacker helper exposed over HTTP on port 8080. It provides /exploit/normal for a benign request and /exploit/attack for malicious delivery. The attack method constructs a CoAP URI with CamelExecCommandExecutable and CamelExecCommandArgs query parameters and sends a GET request using Californium's CoapClient. - README.md thoroughly documents the vulnerability, affected versions, exploitation steps, and mitigation guidance. Main exploit capability: The exploit achieves unauthenticated remote code execution over the network by sending a single CoAP UDP request to the vulnerable route. The core primitive is header injection: CoAP URI query parameters are copied into Camel Exchange headers without filtering in affected camel-coap versions. Because camel-exec honors CamelExecCommandExecutable and CamelExecCommandArgs headers, the attacker can override the configured benign command and execute arbitrary OS commands. The route then returns command stdout in the CoAP response, creating a simple interactive execution channel. Observed exploit flow: 1. Attacker reaches the CoAP service on UDP/5683. 2. Attacker sends a request to /run with malicious query parameters such as CamelExecCommandExecutable=/usr/bin/touch and CamelExecCommandArgs=/tmp/pwned. 3. Vulnerable camel-coap maps those query parameters into Camel headers. 4. Downstream camel-exec consumes those headers and runs the attacker-selected command instead of the configured echo hello. 5. Command output is converted to string and returned to the requester. This is a real exploit reproducer rather than a detector. It includes a working payload path, a reachable network target, and a helper controller that operationalizes exploitation against the local vulnerable service.
Repository contains a multi-PoC assessment for three Apache Camel 4.18.0 vulnerabilities, not a framework module. Structure is split into per-CVE Java applications under poc/cve-2026-33453-coap, poc/cve-2026-40473-mina, and poc/cve-2026-40858-infinispan; a docker-compose lab that exposes the vulnerable services; and three Python exploit scripts under poc/exploits. README.md and EXPLOITS-REPORT.md document root cause, attack flow, and reproduction steps. Main exploit capabilities: - CVE-2026-33453: exploit_cve_2026_33453_coap.py crafts raw CoAP UDP packets and injects CamelExecCommandExecutable/CamelExecCommandArgs as URI query parameters to override camel-exec behavior on /api/status. It is a direct unauthenticated network RCE PoC and parses CoAP responses to display command output. - CVE-2026-40473: exploit_cve_2026_40473_mina.py targets MINA TCP endpoints, especially raw TCP on 9879, and uses ysoserial-generated gadget chains for unsafe Java deserialization. It includes a callback listener to capture command output via HTTP POST/curl from the victim. The Java helper MinaGadgetGenerator builds MINA-compatible serialized gadget bytes, and MinaTestPayload validates wire compatibility. - CVE-2026-40858: exploit_cve_2026_40858_infinispan.py builds a Hot Rod PUT request to write malicious serialized bytes into an Infinispan cache entry used by Camel aggregation. This is a delayed-trigger exploit: code execution occurs when Camel later deserializes the cached object. It can use ysoserial if available or a demo serialized object otherwise. Repository purpose: to demonstrate exploitability of three claimed Apache Camel 4.18.0 issues in a controlled Docker lab. The Java apps intentionally expose vulnerable routes, while the Python scripts operationalize exploitation over UDP/TCP/cache protocols. The code is coherent, aligned with the documented CVEs, and clearly intended as working proof-of-concept exploit material rather than mere detection.
Repository is a multi-PoC research project for three Apache Camel 4.18.0 vulnerabilities, not a framework module. Structure is split into: (1) README and exploit report documenting root cause and reproduction, (2) three Java/Maven vulnerable demo applications under poc/cve-* with Dockerfiles, (3) docker-compose.yml to launch the lab, and (4) three Python exploit scripts under poc/exploits. The CoAP PoC demonstrates unauthenticated header injection over UDP/5683 by crafting raw CoAP packets with URI query parameters that become Camel headers, overriding camel-exec command settings and returning command output. The MINA PoC demonstrates unsafe Java deserialization over TCP on ports 9877/9878/9879; the most important path is 9879 with allowDefaultCodec=false, where raw IoBuffer data is converted into ObjectInputStream without filtering. Supporting Java utilities generate MINA-compatible serialized payloads and test framing. The Python MINA exploit can use ysoserial gadget chains and starts a local HTTP listener to capture exfiltrated command output via curl from the target. The Infinispan PoC demonstrates cache poisoning against a Camel aggregation repository backed by Infinispan; the Python exploit crafts a Hot Rod PUT request to write a malicious serialized object to a predictable cache key, relying on later deserialization by Camel to trigger execution. Overall, this is a real exploit repository with operational PoCs, local lab infrastructure, and clear network targets: CoAP UDP/5683, MINA TCP/9877-9879, and Infinispan Hot Rod TCP/11222.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CWE-915 improper control of dynamically managed code resources/header-injection vulnerability in Apache Camel's camel-coap component. Unfiltered CoAP URI query parameters can become internal Camel Exchange headers; where a route uses a header-sensitive producer such as camel-exec, this can enable unauthenticated remote command execution.
A remote code execution vulnerability affecting Apache Camel camel-coap.
A remote code execution vulnerability in Apache Camel camel-coap via CoAP URI query parameter injection.
A high-severity vulnerability in Apache Camel's camel-coap component that allows unauthenticated header injection via CoAP URI query parameters, which can lead to remote code execution when messages are forwarded to header-sensitive producers such as camel-exec.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.