Executive brief
Apache Camel's Lucene component is used to integrate full-text search capabilities into message routing applications. A flaw in the component allowed HTTP request headers (QUERY and RETURN_LUCENE_DOCS) to bypass Camel's security filtering and directly control the search query executed against an indexed database. An unauthenticated attacker could craft HTTP requests to read unauthorized documents, extract entire indexes, or trigger expensive queries to exhaust CPU resources.
Technical details
The camel-lucene producer reads search queries from an Exchange header named QUERY (and RETURN_LUCENE_DOCS for result formatting), but these header names lack the Camel/camel namespace prefix. The HttpHeaderFilterStrategy only blocks headers in the Camel namespace at HTTP boundaries, allowing these unfiltered headers to pass directly from inbound HTTP requests into the message exchange. In routes exposing Lucene queries through an HTTP consumer (e.g., platform-http), an unauthenticated attacker can set the QUERY header to inject arbitrary search expressions, overriding the route's intended query logic. This enables reading unauthorized documents (e.g., via match-all queries), bypassing per-user access filters, and executing expensive regex queries to consume CPU. The vulnerability affects Camel 4.0.0–4.14.7, 4.15.0–4.18.2, and 4.19.0–4.20.x; patches are available in 4.14.8, 4.18.3, and 4.21.0. After patching, routes must use the Camel-prefixed header names CamelLuceneQuery and CamelLuceneReturnLuceneDocs.
Affected products
- Apache Camel 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.x
- Apache Camel Lucene >=4.0.0, <4.14.8; >=4.15.0, <4.18.3; >=4.19.0, <4.21.0
Timeline
- 2026-07-06: disclosed
- 2026-07-06: patched: Patches released in Camel 4.14.8, 4.18.3, and 4.21.0