Executive brief
Apache Camel's WebSocket component fails to filter control headers from inbound WebSocket query parameters, allowing an unauthenticated attacker to inject Camel-internal headers. By supplying malicious query parameters such as CamelHttpUri, an attacker can redirect downstream HTTP requests to arbitrary destinations (server-side request forgery) and trigger disclosure of sensitive data including environment variables, application properties, and secrets through placeholder resolution.
Technical details
The vulnerability exists in the camel-atmosphere-websocket component's WebsocketConsumer class, which copies query-string parameters directly into the Camel Exchange header map without applying a HeaderFilterStrategy. This allows externally supplied WebSocket query parameters to override Camel-internal control headers such as CamelHttpUri (Exchange.HTTP_URI). When a route chains the WebSocket consumer into a downstream HTTP producer, an attacker can inject a crafted CamelHttpUri header via query parameters to redirect the server-side HTTP request to an attacker-controlled destination (SSRF). Additionally, the HTTP producer resolves Camel property placeholders in the resulting URI, exposing environment variables, application properties, and vault secrets to the attacker. The vulnerability is network-reachable and requires no authentication if the WebSocket endpoint is exposed without authentication controls. Patches are available in versions 4.14.8 (LTS), 4.18.3, and 4.21.0.
Affected products
- Apache Camel 4.0.0 to <4.14.8, 4.15.0 to <4.18.3, 4.19.0 to <4.21.0
Timeline
- 2026-07-06: disclosed: Vulnerability disclosed via GitHub Advisory Database
- 2026-07-06: patched: Patches released in versions 4.14.8, 4.18.3, and 4.21.0