Executive brief
Apache Camel, a popular integration framework used to connect different software systems, is vulnerable to a critical security flaw. An attacker with access to messaging services (like JMS) can bypass security filters by using unusual capitalization in message headers. This could allow them to execute unauthorized commands or write malicious files on the server, potentially leading to a full system takeover.
Technical details
This vulnerability is an incomplete fix for CVE-2025-27636. While HTTP strategies were previously patched to handle case-sensitivity, five non-HTTP HeaderFilterStrategy implementations (JmsHeaderFilterStrategy, ClassicJmsHeaderFilterStrategy, SjmsHeaderFilterStrategy, CoAPHeaderFilterStrategy, and GooglePubsubHeaderFilterStrategy) remained case-sensitive. Because Camel Exchange stores headers in a case-insensitive map but these strategies used case-sensitive prefix filtering (e.g., String.startsWith('Camel')), an attacker with producer access to a broker can inject headers like 'CAmelExecCommandExecutable'. Downstream components such as camel-exec and camel-file resolve these using canonical casing, leading to Remote Code Execution (RCE) or arbitrary file writes. The issue is resolved by applying setLowerCase(true) to the affected strategies.
Affected products
- Apache Camel 3.0.0 before 4.14.6, 4.15.0 before 4.18.2, 4.19.0 before 4.20.0
- Red Hat Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 3.27
- Red Hat Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 4.18
- Red Hat Red Hat build of Apache Camel 4 for Quarkus 3 3
Timeline
- 2026-04-27: advisory: Initial advisory published by Apache and NVD
- 2026-05-14: patched: Red Hat released security updates for affected Camel builds
References
- https://repo.maven.apache.org/maven2
- https://camel.apache.org/security/CVE-2026-40453.html
- https://access.redhat.com/errata/RHSA-2026:17668
- https://access.redhat.com/errata/RHSA-2026:19835
- https://access.redhat.com/security/cve/CVE-2026-40453
- https://bugzilla.redhat.com/show_bug.cgi?id=2463173
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40453.json