Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilityinternet-facing-service-vulnerabilityidentity-authentication-vulnerabilitywidely-deployed-product-advisory

Apache Camel flaws expose mail, CoAP, JMS, and HTTP routes to RCE and auth bypass

Updated 2mo agoFirst seen Apr 26, 20267 sources

Apache disclosed four vulnerabilities in Apache Camel affecting message handling and request protection across multiple components. The most severe issues, CVE-2026-33453 and CVE-2026-33454, allow attackers to inject Camel internal headers through untrusted inputs that are copied into the Exchange without proper inbound filtering. In camel-coap, a single unauthenticated UDP packet can place arbitrary query parameters into Exchange headers, enabling pre-authentication remote code execution when routes forward data to header-sensitive components such as camel-exec, camel-sql, camel-bean, camel-file, or template processors. In camel-mail, emails received over IMAP or POP3 can carry crafted MIME headers with the Camel prefix that reach downstream components and similarly influence execution, making remote code execution possible in vulnerable deployments.

Share:
Apache Camel flaws expose mail, CoAP, JMS, and HTTP routes to RCE and auth bypass
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 26, 20262mo ago

Apache Camel discloses CVE-2026-40453 incomplete fix in header filtering

Apache disclosed an important-severity vulnerability caused by an incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategy implementations including camel-jms, camel-sjms, camel-coap, and camel-google-pubsub. The bug allows case-variant internal header injection that can lead to remote code execution or arbitrary file write in affected routes.

Apache Camel discloses CVE-2026-40022 auth bypass in camel-platform-http-main

Apache disclosed a moderate-severity authentication bypass in camel-platform-http-main affecting non-root context paths when the authentication path is not explicitly set. The flaw can expose protected routes and management endpoints, and Apache recommended upgrading affected 4.14.x and 4.18.x releases.

Apache Camel discloses CVE-2026-33454 in camel-mail

Apache disclosed an important-severity flaw in camel-mail where inbound MIME headers are not filtered, allowing attackers to inject Camel-specific headers via email and potentially trigger downstream remote code execution. Apache said affected versions include 3.0.0 before 4.14.6 and 4.15.0 before 4.18.1, and credited Hyunwoo Kim.

Apache Camel discloses CVE-2026-33453 in camel-coap

Apache disclosed a high-severity vulnerability in the camel-coap component that allows CoAP URI query parameters to be injected into Camel Exchange headers, enabling single-packet pre-authentication RCE in vulnerable routes. The issue affects camel-coap 4.14.0 through 4.14.5, 4.18.0 before 4.18.1, and 4.19.0, and was credited to Hyunwoo Kim.

Mar 20, 20263mo ago

Apache Camel fixes camel-coap header filtering issue in supported branches

Apache Camel resolved a camel-coap issue in JIRA where CoAP query parameters were mapped to Camel Exchange headers without a HeaderFilterStrategy. The fix was released in versions 4.14.6 and 4.18.1 and tracked through coordinated pull requests across supported branches.

[CAMEL-23222] camel-coap: Integrate HeaderFilterStrategy for CoAP query parameter to header mapping - ASF Jira
SOURCE COVERAGE

Sources

7 references tracked. Mallory keeps watching after this page renders.

7 SOURCESView all
Cvefeed High SeverityAdvisories
Apr 27, 2026

CVE-2026-33454 - Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)

cvefeed.io

Open source
Cvefeed High SeverityAdvisories
Apr 27, 2026

CVE-2026-33453 - Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution

cvefeed.io

Open source
Oss Security Mailing ListNews
Apr 26, 2026

oss-sec: CVE-2026-33453: Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution

seclists.org

Open source
Oss Security Mailing ListNews
Apr 26, 2026

oss-sec: CVE-2026-33454: Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)

seclists.org

Open source
Oss Security Mailing ListNews
Apr 26, 2026

oss-sec: CVE-2026-40453: Apache Camel: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection

seclists.org

Open source
Oss Security Mailing ListNews
Apr 26, 2026

oss-sec: CVE-2026-40022: Apache Camel: Camel-Platform-HTTP-Main: Authentication Bypass on Non-Root Context Paths in camel main runtime

seclists.org

Open source
Apache JiraNews
Mar 20, 2026

[CAMEL-23222] camel-coap: Integrate HeaderFilterStrategy for CoAP query parameter to header mapping - ASF Jira

issues.apache.org

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Apache Camel flaws expose mail, CoAP, JMS, and HTTP routes to RCE and auth bypass | Mallory