CVE-2026-46584 is an improper input validation vulnerability in the Apache Camel Mail component's SMTP/SMTPS producer. MailProducer.getSender processes message headers in the Camel-internal mail.smtp.* and mail.smtps.* namespaces as per-message JavaMail session properties, overriding endpoint configuration. These headers were not blocked by a HeaderFilterStrategy and could therefore be propagated from untrusted inbound protocols to a mail producer. Before Camel 4.19.0, an attacker could override the SMTP host and redirect the connection. In Camel 4.19.0 and later, the configured endpoint host is explicitly selected, preventing host redirection, but attacker-controlled session properties can still weaken transport protections or alter proxy behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept for CVE-2026-46584 in Apache Camel's camel-mail component. It is a real exploit reproducer, not just documentation or detection logic. The core issue is that affected camel-mail versions accept inbound Exchange headers prefixed with mail.smtp. or mail.smtps. and merge them into the JavaMail Session for a send operation. In this PoC, attacker-controlled HTTP headers are passed through Camel's platform-http ingress into the Exchange, allowing per-request manipulation of SMTP transport behavior. Repository structure is compact and purpose-built: Application.java starts the Spring Boot app; VictimRoute.java defines the vulnerable Camel route from platform-http:/send to smtp://127.0.0.1:2525 with hardcoded victim credentials; LegitSmtpServer.java implements a minimal legitimate SMTP server on port 2525 that accepts AUTH LOGIN and records credentials; AttackerSocksProxy.java implements a minimal SOCKS5 proxy on port 1080 that transparently forwards SMTP traffic while sniffing AUTH LOGIN base64 credentials; ExploitController.java provides an HTTP endpoint that first triggers a benign request and then an exploit request with injected mail.smtp.socks.host and mail.smtp.socks.port headers to prove credential theft. Supporting files include pom.xml pinning vulnerable camel-mail 4.18.2, application.properties setting server.port=8080, and Docker artifacts for containerized execution. Main exploit capability: credential theft via on-path interception. The exploit does not need direct SMTP access or code execution on the target. It only needs the ability to send HTTP requests with chosen headers to a vulnerable Camel route. By injecting mail.smtp.socks.host=127.0.0.1 and mail.smtp.socks.port=1080, the victim's authenticated SMTP session is tunneled through the attacker proxy, which captures the victim's SMTP AUTH LOGIN username and password while still relaying the message successfully to the legitimate SMTP server. The README also notes adjacent abuse possibilities through other injectable JavaMail properties, including TLS trust weakening, server identity check disabling, STARTTLS downgrade, and envelope sender spoofing. Overall, this is an operational PoC demonstrating a web-to-network attack chain: attacker-controlled HTTP headers influence backend SMTP transport settings in Camel, enabling interception and theft of configured mail credentials.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-exposure and information-disclosure vulnerability in Apache Camel Mail Component caused by improper validation of mail headers.
An Apache Camel Mail Component vulnerability that can expose credentials and disclose information through improper mail-header input validation.
An improper-input-validation and sensitive-information-exposure vulnerability in Apache Camel's camel-mail producer. Untrusted message headers in the mail.smtp.* or mail.smtps.* namespace can override JavaMail session properties. In versions before 4.19.0, this can redirect SMTP connections and expose configured SMTP credentials; in later versions, it can weaken transport security or enable interception of outbound messages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.