Junglewise Threat Intelligence

CVE-2026-46726: Apache Camel SSRF and secret disclosure in Vertx Websocket

CVE-2026-46726 · Severity: high · CVSS 7.5 · Published 2026-07-06

Technologies: Apache Camel. Vendors: Apache.

Executive brief

Apache Camel's WebSocket component for Vertx receives query and path parameters from incoming WebSocket connections and copies them directly into internal message headers without any security filtering. An attacker can inject special Camel control headers (like CamelHttpUri) to redirect HTTP requests sent by downstream components to arbitrary destinations, or leak environment variables and application secrets through property placeholder resolution. This is exploitable by any unauthenticated remote user if the WebSocket endpoint is exposed without access controls.

Technical details

The vulnerability exists in VertxWebsocketConsumer.populateExchangeHeaders(), which maps inbound WebSocket query and path parameters into Camel Exchange headers without applying a HeaderFilterStrategy. This allows an unauthenticated remote attacker to inject arbitrary Camel-namespaced headers (Camel* or camel*) via query parameters. When such headers—particularly CamelHttpUri (Exchange.HTTP_URI)—reach a downstream HTTP producer, they override the target URI and redirect the request to an attacker-controlled destination (SSRF attack). Furthermore, the HTTP producer resolves Camel property placeholders (e.g., ${env:ENV_VAR}, ${properties:app.prop}, ${vault:secret}) within the attacker-supplied URI, disclosing environment variables, application properties, and vault secrets to the attacker. Attack preconditions include an unauthenticated WebSocket endpoint and a route architecture where a WebSocket consumer feeds an HTTP producer. Patches have been released in versions 4.14.8, 4.18.3, and 4.21.0, which implement HeaderFilterStrategy to filter Camel-namespaced headers on inbound mapping.

Affected products

  • Apache Camel 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.x

Timeline

  • 2026-07-06: disclosed: Published by GitHub Advisory Database and NVD
  • 2026-07-06: patched: Patches released in versions 4.14.8, 4.18.3, and 4.21.0

References

Related threats