CVE-2026-55994 is an improper input-validation flaw in Apache Camel's Camel-Iggy component. Vulnerable Iggy consumers copy user-controlled inbound message headers into the Camel Exchange without applying a HeaderFilterStrategy. A publisher to a consumed Iggy stream or topic can therefore inject Camel control headers, including the HTTP target-URI control header. When the consumer route forwards the exchange to an HTTP producer, the injected value can override the outbound request destination. The HTTP producer may also resolve property placeholders within the attacker-controlled URI, causing resolved environment variables, application properties, or vault-held secrets to be included in an outbound request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-55994 in Apache Camel's camel-iggy component. It is a real exploit PoC, not merely documentation or detection logic. The core issue is that IggyFetchRecords.createExchange copies attacker-controlled Iggy user-headers directly onto a Camel Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers such as CamelHttpUri. When the resulting Exchange is sent into a camel-http producer, the attacker can override the intended destination URI, producing SSRF. Because the HTTP producer also resolves Camel property placeholders in the injected URI, the exploit additionally demonstrates disclosure of secrets such as application properties. Repository structure is small and focused: Application.java is the Spring Boot entry point; VictimRoute.java defines the downstream Camel route from direct:iggy-delivery to http://localhost:8080/legit-backend; SinkController.java exposes local HTTP endpoints /legit-backend, /internal/secret, and /collect to observe exploit effects; ExploitController.java is the main exploit driver and the most important file, exposing GET /exploit/attack. That controller constructs a real IggyEndpoint/IggyConsumer/IggyFetchRecords instance, uses reflection to invoke the private vulnerable createExchange method on forged Iggy Message objects, and then forwards the resulting poisoned Exchange into the victim route. It runs three scenarios: benign header delivery, SSRF via CamelHttpUri=http://localhost:8080/internal/secret, and secret exfiltration via CamelHttpUri=http://localhost:8080/collect?leak={{app.secret}}. application.properties defines app.secret=SUPER-SECRET-abc123, which is leaked through placeholder resolution. The exploit capability is therefore twofold: arbitrary server-side HTTP redirection within the context of the Camel route, and disclosure of sensitive configuration values through outbound requests. The PoC is operational because it includes working payloads and a complete local harness, but it is not weaponized into a broader framework. It targets Apache Camel camel-iggy affected versions described in the README: from 4.17.0 before 4.18.3 and from 4.19.0 before 4.21.0. The Dockerfile and docker-compose.yml package the app as a single service on port 8080 for easy reproduction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.