CVE-2026-49098 is an improper input validation vulnerability in Apache Camel's camel-kafka component. Kafka producer control headers used non-Camel-prefixed names, allowing headers supplied by an upstream HTTP consumer to bypass that consumer's filtering and reach the Kafka producer in multi-component routes. The producer prioritizes an override-topic header over the endpoint-configured topic, permitting untrusted input to redirect a message. Related control headers can also influence message timestamps and Kafka partition selection. Affected versions are Apache Camel 4.0.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-49098 in Apache Camel's camel-kafka component. It is a real exploit PoC, not just documentation or detection logic. The core issue is that an upstream HTTP request can supply the non-Camel-prefixed header kafka.OVERRIDE_TOPIC, which survives the HTTP header filter and is later consumed by Camel's KafkaProducer.evaluateTopic(), overriding the route's configured Kafka topic. Repository structure is small and focused: Application.java starts the Spring Boot app; VictimRoute.java defines the vulnerable Camel route from platform-http:/feedback to kafka:user-feedback; MockKafkaClientFactory.java replaces the real Kafka transport with Kafka's MockProducer so no broker is required; KafkaFactoryConfig.java registers that mock factory; ExploitController.java acts as the attacker driver and exposes /exploit/attack to automatically perform both a benign and malicious request and print the resulting produced topics. Supporting files include pom.xml with Camel 4.18.2 dependencies, Dockerfile and docker-compose.yml for containerized execution, and application.properties for port/logging configuration. Main exploit capability: cross-topic message injection. The exploit sends a POST to /feedback with header kafka.OVERRIDE_TOPIC: account-commands and a forged JSON command body. Although the route is configured to publish only to user-feedback, the produced record is redirected to account-commands. This demonstrates integrity impact against downstream consumers of privileged topics. The README also notes related injectable headers such as kafka.OVERRIDE_TIMESTAMP and kafka.PARTITION_KEY. Operationally, the exploit is easy to run and produces direct proof of exploitation by inspecting MockProducer history. It does not require a live Kafka broker, credentials, or shell payloads. The result is attacker-controlled message placement into arbitrary Kafka topics reachable through the vulnerable route design.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.