CVE-2026-55993 is an improper input-validation vulnerability in Apache Camel's camel-atmosphere-websocket consumer. The consumer copied inbound WebSocket query parameters into the Camel Exchange header map without applying its inherited HeaderFilterStrategy. An attacker could therefore inject Camel internal control headers, including the HTTP target-URI header. When a route forwards this consumer input to an HTTP producer, the injected header can override the intended outbound URI. The HTTP producer can also resolve Camel property placeholders within the attacker-controlled URI, enabling disclosure of values derived from environment variables, application properties, or vault-backed secrets. Affected versions are 4.0.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Spring Boot/Apache Camel proof-of-concept reproducer for CVE-2026-55993, a header-injection flaw in Apache Camel's camel-atmosphere-websocket component. The core issue is that WebsocketConsumer copies WebSocket query parameters into Camel Exchange headers without a HeaderFilterStrategy. If a route forwards those events into camel-http, an attacker can inject CamelHttpUri in the WebSocket query string and override the HTTP producer destination, yielding SSRF. Because camel-http also resolves Camel property placeholders on the attacker-controlled URI, the exploit additionally demonstrates disclosure of secrets such as application properties. Repository structure is small and focused: Application.java is the Spring Boot entry point; VictimRoute.java defines the vulnerable route from atmosphere-websocket:///feed to http://localhost:8080/legit-backend; SinkController.java implements local verification endpoints (/legit-backend, /internal/secret, /collect, /collect/{secret}) to observe where the server-side request actually goes; ExploitController.java is the main exploit logic and uses reflection to invoke the real vulnerable WebsocketConsumer.getQueryMap(String) and sendEventNotification(...) methods with attacker-controlled query strings. This direct invocation is necessary because the tested Atmosphere/JSR-356 transport path does not populate the vulnerable query map in a live WebSocket session for this version. The exploit capabilities are operational but basic: a GET request to /exploit/attack runs three scenarios—benign routing, SSRF to /internal/secret, and secret disclosure via injected CamelHttpUri=http://localhost:8080/collect/{{app.secret}}. The application.properties file seeds the secret value (SUPER-SECRET-abc123), and the exploit verifies that the resolved value reaches the attacker-controlled collector endpoint. Dockerfile and docker-compose.yml package the reproducer as a single service on port 8080. This is a genuine exploit reproducer rather than a scanner or detection script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A distinct vulnerability in the Apache Camel Atmosphere Websocket component concerning the consumer-side query-parameter path. No further technical details are provided.
An unauthenticated remote SSRF and sensitive-information disclosure vulnerability in Apache Camel's Atmosphere WebSocket component. Externally supplied WebSocket query parameters could inject Camel control headers, including CamelHttpUri, into a Camel Exchange. In routes forwarding to HTTP producers, this could redirect server-side requests and exfiltrate resolved property-placeholder values.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.