CVE-2026-71300 is an improper input-validation vulnerability in Apache Camel's camel-atmosphere-websocket component. In affected releases, WebSocket peer-dispatch headers used by the producer were named outside the Camel namespace and were therefore not filtered by the inherited HTTP header-filtering strategy. When an HTTP consumer route forwards requests to an atmosphere-websocket producer, an external sender can inject a list-valued dispatch header. Because the producer evaluates that header before the route-selected single-recipient header, the injected value can override the intended WebSocket recipient selection. The issue affects Apache Camel versions 4.0.0 through 4.14.8, 4.15.0 through 4.18.3, and 4.19.0 through 4.21.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a runnable Spring Boot proof-of-concept for CVE-2026-71300 in Apache Camel's camel-atmosphere-websocket component. It is a real exploit reproducer rather than a scanner: it sets up an HTTP-to-WebSocket Camel route and demonstrates that an attacker can inject websocket.connectionKey.list through HTTP headers to override the route's intended websocket.connectionKey recipient. The result is message redirection from a victim WebSocket peer to an attacker-chosen peer. Repository structure is small and focused. The root README explains the vulnerability, affected/fixed versions, and how to run the demo. The camel-spring-boot subdirectory contains the runnable application: Application.java registers the Camel WebSocket servlet at /ws/*; NotifyRoute.java defines the vulnerable bridge from platform-http:/notify to atmosphere-websocket:///live?servletName=CamelWsServlet and pins delivery to victim-connection-key; StorePopulator.java inserts two stand-in WebSocket peers into the endpoint store; RecordingWebSocket.java records delivered messages; WebsocketStoreAccessor.java exposes package-private store access; and ExploitController.java provides /exploit/attack, which sends one benign POST and one malicious POST with duplicated websocket.connectionKey.list headers to http://localhost:8080/notify and then verifies that the attacker peer received the victim's message. The exploit capability is dispatch hijacking, not code execution. It abuses header precedence in WebsocketProducer.process: websocket.connectionKey.list is evaluated before websocket.connectionKey, and because the vulnerable header names are outside the Camel namespace, the HTTP HeaderFilterStrategy does not strip them. This allows an external sender to influence recipient selection across the HTTP-to-WebSocket bridge. The PoC is operational because it includes a working payload and end-to-end demonstration logic, but it is not weaponized or framework-based.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.