Junglewise Threat Intelligence

CVE-2026-55994: Apache Camel SSRF and Information Disclosure in Iggy component

CVE-2026-55994 · Severity: high · CVSS 7.5 · Published 2026-07-06

Technologies: Apache Camel. Vendors: Apache Software Foundation, Apache.

Executive brief

Apache Camel's Iggy message component fails to filter untrusted message headers before copying them into the routing framework's control namespace. An attacker with the ability to publish to a monitored Iggy stream can inject special headers (such as CamelHttpUri) that redirect HTTP requests to arbitrary destinations, or trigger disclosure of environment variables and secrets through property placeholder resolution.

Technical details

The camel-iggy consumer component copies inbound Iggy message user-headers directly into the Camel Exchange header map without applying any filtering via HeaderFilterStrategy. This allows an attacker able to publish to the consumed Iggy topic/stream to inject Camel-reserved control headers (case-insensitive Camel* / camel* namespace). When an injected header like CamelHttpUri reaches a downstream HTTP producer, it redirects the server-side HTTP request to an attacker-controlled destination—enabling SSRF attacks against internal services or metadata endpoints. The HTTP producer further resolves property placeholders in the injected URI, disclosing environment variables, application properties, and vault secrets to the attacker. The vulnerability requires the ability to publish to the Iggy stream/topic and a route architecture in which the Iggy consumer directly feeds an HTTP producer. Fixed in Camel 4.21.0 and 4.18.3 via an IggyHeaderFilterStrategy that filters the Camel header namespace case-insensitively on inbound mapping.

Affected products

  • Apache Camel 4.17.0 to 4.18.2, 4.19.0 to 4.20.x

Timeline

  • 2026-07-06: disclosed: Vulnerability disclosed via GitHub advisory GHSA-pw9q-pq7c-rfqw
  • 2026-07-06: patched: Patches released for Camel 4.18.3 and 4.21.0

References

Related threats