GHSA-5g68-f6xg-vf2rHighCVSS 7.3

Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

Published
July 6, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Input Validation vulnerability in Apache Camel.

This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.

Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.

🎯 Affected products3

  • maven/org.apache.camel:camel-couchdb:>= 4.0.0, < 4.14.8
  • maven/org.apache.camel:camel-couchdb:>= 4.15.0, < 4.18.3
  • maven/org.apache.camel:camel-couchdb:>= 4.19.0, < 4.21.0

🔗 References (13)