CVE-2026-46456 is an improper input validation vulnerability in Apache Camel's camel-aws2-sqs component. Sqs2HeaderFilterStrategy configured an outbound header filter but no inbound filter. When Sqs2Consumer maps SQS message attributes into a Camel Exchange, the default inbound behavior permits arbitrary attribute names, including Camel-internal control headers. A sender able to submit a message to a consumed SQS queue can inject Camel control headers that persist across internal direct, seda, and vm route hops and can influence downstream producers. Affected versions are Apache Camel 4.0.0 through before 4.14.8, 4.15.0 through before 4.18.3, and 4.19.0 through before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot proof-of-concept reproducer for CVE-2026-46456, an Apache Camel camel-aws2-sqs inbound message-attribute header injection vulnerability. It is not just a detector: it sets up a vulnerable Camel route, provides an attacker-trigger endpoint, and demonstrates downstream command execution. Repository structure is small and purpose-built. Application.java is the Spring Boot entry point. SqsConfig.java builds a shared AWS SDK v2 SqsClient pointed at LocalStack via AWS_ENDPOINT or default http://localhost:4566. VictimRoute.java defines the vulnerable Camel route: it consumes from aws2-sqs://cve with messageAttributeNames=All and forwards each message to exec:echo?args=hello. ExploitController.java acts as the attacker primitive: a GET request to /exploit/attack creates or resolves the queue URL, sends an SQS message with crafted message attributes CamelExecCommandExecutable and CamelExecCommandArgs, then waits for /tmp/pwned to appear as proof that the downstream exec producer honored the injected headers. The exploit capability is header injection leading to command execution. The core issue is that affected camel-aws2-sqs versions filter outbound Camel headers but do not properly filter inbound SQS message attributes before mapping them onto Camel Exchange headers. Any sender with sqs:SendMessage to the consumed queue can inject Camel control headers such as CamelExecCommandExecutable, CamelExecCommandArgs, CamelHttpUri, CamelFileName, or CamelSqlQuery to steer downstream producers. In this PoC, the payload is operational but basic: it hardcodes /usr/bin/touch /tmp/pwned to prove RCE. Deployment artifacts include docker-compose.yml and Dockerfile. docker-compose starts LocalStack SQS on port 4566 and the reproducer app on port 8080. pom.xml pins Camel 4.18.2, an affected version, and includes camel-aws2-sqs-starter, camel-exec-starter, camel-spring-boot-starter, and AWS SDK SQS. application.properties sets server.port=8080 and Camel app naming. Overall, this is a credible operational PoC for a cloud/network attack path against Apache Camel integrations that consume SQS message attributes and pass messages to header-sensitive downstream producers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Apache Camel camel-aws2-sqs component vulnerability that permits SQS message senders to inject Camel-internal control headers into inbound exchanges. These headers can influence downstream route producers, including HTTP destinations, file names, or SQL queries, depending on route configuration.
A related vulnerability in Apache Camel's camel-aws2-sqs component where an inbound header filtering gap was exploitable, allowing injection of Camel control headers via inbound SQS message attributes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.