CVE-2026-46588 is an improper input validation vulnerability in Apache Camel's CouchDB component. Non-Camel-prefixed Exchange headers can bypass the configured HeaderFilterStrategy and influence operation selection at a CouchDB endpoint. This permits untrusted input that reaches Exchange headers to override the intended CouchDB operation. Affected releases are Apache Camel through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Java/Spring Boot proof-of-concept reproducer for CVE-2026-46588, a header-injection flaw in Apache Camel's `camel-couchdb` component. The exploit is not a generic framework module; it is a self-contained demo app composed of a vulnerable Camel route, a direct CouchDB harness, and a controller that performs the attack sequence. Repository structure: `Application.java` is the Spring Boot entry point. `VictimRoute.java` defines the vulnerable Camel route `platform-http:/ingest` that removes only `Camel*` headers, converts the body to string, and forwards requests to a CouchDB producer endpoint. `CouchDbSettings.java` centralizes host, port, database, credentials, and the secret document ID. `CouchDbHarness.java` talks directly to CouchDB over HTTP to create the database, seed a sensitive document, and verify whether it can be read or deleted. `ExploitController.java` is the attacker component; it exposes `/exploit/attack` and programmatically sends crafted POST requests to `/ingest` with injected `CouchDbMethod` and `CouchDbId` headers. Supporting files include `docker-compose.yml` for CouchDB plus app deployment, `Dockerfile`, `pom.xml`, and `application.properties`. Main exploit capability: operation confusion through HTTP header injection. The vulnerable route is intended to be write-only, but because Camel's inbound HTTP header filtering blocks `Camel*` headers rather than `CouchDb*`, attacker-supplied `CouchDbMethod` and `CouchDbId` survive the boundary and are consumed by `CouchDbProducer`. The exploit first performs disclosure by sending `CouchDbMethod=GET` and `CouchDbId=admin-secret`, causing the route to return the protected document and leak its `_rev`. It then performs destruction by sending `CouchDbMethod=DELETE` with a body containing the leaked `_rev`, deleting the protected document. This is a real exploit reproducer rather than a detector, and the payload is basic/hardcoded, making maturity best classified as OPERATIONAL. Fingerprintable infrastructure and targets include the local victim endpoint `http://127.0.0.1:8080/ingest`, the helper trigger endpoint `/exploit/attack`, CouchDB on port 5984 (`127.0.0.1` locally or `couchdb` in Docker), database `cameldb`, and document ID `admin-secret`. The repo also hardcodes demo credentials `admin:password` for the local Compose environment. Overall, the repository's purpose is to demonstrate that an unauthenticated HTTP client can transform a write-only Camel-to-CouchDB ingestion route into arbitrary read/delete behavior by injecting `CouchDb*` control headers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.