Junglewise Threat Intelligence

CVE-2026-46584: Apache Camel Mail information exposure via SMTP header injection

CVE-2026-46584 · Severity: low · CVSS 3.7 · Published 2026-07-06

Technologies: Apache Camel. Vendors: Apache Software Foundation, Apache.

Executive brief

Apache Camel's Mail component allows attackers to inject malicious SMTP configuration headers that override the intended mail server settings. On older versions (before 4.19.0), attackers can redirect email traffic to their own server and steal credentials; on newer versions, they can downgrade transport security or intercept messages. This attack requires a route that accepts untrusted input (such as HTTP query parameters or message queues) and sends email without filtering dangerous headers.

Technical details

The MailProducer.getSender method scans outgoing Exchange message headers for mail.smtp.* and mail.smtps.* namespaced properties and applies them as JavaMail session properties, overriding endpoint configuration. The Camel-internal namespace is not blocked by HeaderFilterStrategy, allowing untrusted sources (HTTP query parameters, JMS/Kafka messages) to inject these headers. Impact varies: pre-4.19.0 releases allow attacker-controlled mail.smtp.host to redirect SMTP connections to attacker infrastructure, transmitting endpoint credentials; 4.19.0+ releases connect to the configured host but permit weakening of transport security (ssl.trust, starttls.enable, socks.host) and message interception. Exploitation requires a route that feeds untrusted input to an smtp/smtps producer without intervening removeHeaders filtering. Patches are available in versions 4.14.8, 4.18.3, and 4.21.0, with the override disabled by default post-patch and configurable only via useJavaMailSessionPropertiesFromHeaders=true.

Affected products

  • Apache Camel 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.x

Timeline

  • 2026-07-06: disclosed: Vulnerability published
  • 2026-07-06: patched: Patches available: versions 4.14.8, 4.18.3, 4.21.0

References

Related threats