CVE-2026-48205 is an improper input validation vulnerability in the Apache Camel camel-dns component. DNS producers accepted DNS resolver and lookup parameters from Exchange headers using non-Camel-prefixed names, which were not blocked by the HTTP header filtering strategy. In routes bridging an HTTP consumer to a dns: producer, attacker-supplied HTTP headers could control the DNS resolver and lookup targets. Affected versions are Apache Camel 4.0.0 through versions before 4.14.8, 4.15.0 through versions before 4.18.3, and 4.19.0 through versions before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-48205 in Apache Camel's camel-dns component. It is a real exploit demonstration, not just documentation or detection logic. The core issue is that vulnerable Camel versions accept non-Camel-prefixed control headers such as dns.server, dns.name, dns.type, dns.class, and term from inbound HTTP requests. Because HttpHeaderFilterStrategy only filters Camel/camel-prefixed headers, an attacker can inject dns.server through an HTTP request and cause the downstream dns:dig producer to instantiate a resolver pointing to an attacker-controlled DNS server, resulting in DNS-based SSRF. Repository structure: Application.java is the Spring Boot entry point. VictimRoute.java defines the vulnerable Camel route from platform-http:/lookup to dns:dig and sets dns.name=example.com, dns.type=A, and dns.class=IN. ExploitController.java acts as the attacker driver by exposing /exploit/attack, which first sends a benign request to /lookup and then a malicious request with header dns.server: 127.0.0.1 to prove redirection. FakeDnsServer.java implements a minimal attacker-controlled DNS server on UDP/53 that records whether it was queried and what name was requested, then returns a minimal DNS response so the victim resolver does not hang. application.properties binds the app to port 8080. Dockerfile and docker-compose.yml package the entire demo into one container. Main exploit capability: unauthenticated web-to-network pivot via header injection. An HTTP client can influence server-side DNS resolution performed by Camel, redirecting it to an attacker-controlled resolver. In the demo, the exploit proves this by causing the victim route to query the local fake DNS server at 127.0.0.1:53, which logs the requested name example.com. The README also correctly notes secondary impact: by controlling dns.name or dns.domain, an attacker could probe internal hostnames; by controlling the resolver, the attacker could observe queries and potentially return poisoned DNS answers. The exploit is operational rather than weaponized: it includes working code and a payload path, but it is a focused reproducer with hardcoded endpoints rather than a generalized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.