Executive brief
Apache Camel's WebSocket component for Vertx receives query and path parameters from incoming WebSocket connections and copies them directly into internal message headers without any security filtering. An attacker can inject special Camel control headers (like CamelHttpUri) to redirect HTTP requests sent by downstream components to arbitrary destinations, or leak environment variables and application secrets through property placeholder resolution. This is exploitable by any unauthenticated remote user if the WebSocket endpoint is exposed without access controls.
Technical details
The vulnerability exists in VertxWebsocketConsumer.populateExchangeHeaders(), which maps inbound WebSocket query and path parameters into Camel Exchange headers without applying a HeaderFilterStrategy. This allows an unauthenticated remote attacker to inject arbitrary Camel-namespaced headers (Camel* or camel*) via query parameters. When such headers—particularly CamelHttpUri (Exchange.HTTP_URI)—reach a downstream HTTP producer, they override the target URI and redirect the request to an attacker-controlled destination (SSRF attack). Furthermore, the HTTP producer resolves Camel property placeholders (e.g., ${env:ENV_VAR}, ${properties:app.prop}, ${vault:secret}) within the attacker-supplied URI, disclosing environment variables, application properties, and vault secrets to the attacker. Attack preconditions include an unauthenticated WebSocket endpoint and a route architecture where a WebSocket consumer feeds an HTTP producer. Patches have been released in versions 4.14.8, 4.18.3, and 4.21.0, which implement HeaderFilterStrategy to filter Camel-namespaced headers on inbound mapping.
Affected products
- Apache Camel 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.x
Timeline
- 2026-07-06: disclosed: Published by GitHub Advisory Database and NVD
- 2026-07-06: patched: Patches released in versions 4.14.8, 4.18.3, and 4.21.0