CVE-2026-33454Disclosure(apache / camel)

MEDIUMCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel application consumes mail through camel-mail (for example via from(\"imap://...\") or from(\"pop3://...\")) the inbound filter check is skipped and Camel-prefixed MIME headers are mapped unfiltered into the Exchange. An attacker who can deliver an email to a mailbox monitored by such a consumer can inject Camel-specific headers that, for some Camel components downstream of the mail consumer (such as camel-bean, camel-exec, or camel-sql), can alter the behaviour of the route. This is the same pattern that was previously addressed in camel-undertow (CVE-2025-30177) and the broader incoming-header filter (CVE-2025-27636 and CVE-2025-29891). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.1. Users are recommended to upgrade to version 4.19.0, which fixes the issue. If users are on the 4.18.x LTS releases stream, then they are suggested to upgrade to 4.18.1. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502CWE-1173

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 1 mentions (2026-04-26); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-05-03: 1Mentions · 2026-05-14: 1Mentions · 2026-07-06: 1Mentions · 2026-07-08: 1Mentions · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-08: 1Exploit Tool / Code · 2026-07-06: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-03: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-11: 104-2604-2704-2805-0305-1407-0607-0807-11
Signal classification4 categories
Disclosure
337.5%
General
225.0%
PoC
225.0%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-271
Disclosure1
2026-04-281
Disclosure1
2026-05-031
Disclosure1
2026-05-141
General1
2026-07-061
PoC1
2026-07-081
PoC1
2026-07-111
Patch1
Full discourse8 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-33454 PT ID: PT-2026-35384 Vendor: Apache Software Foundation Product: Apache Camel Description: The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel application consumes mail through camel-mail (for example via from(\"imap://...\") or from(\"pop3://...\")) the inbound filter check is skipped and Camel-prefixed MIME headers are mapped unfiltered into the Exchange. An attacker who can deliver an email to a mailbox monitored by such a consumer can inject Camel-specific headers that, for some Camel components downstream of the mail consumer (such as camel-bean, camel-exec, or camel-sql), can alter the behaviour of the route. This is the same pattern that was previously addressed in camel-undertow (CVE-2025-30177) and the broader incoming-header filter (CVE-2025-27636 and CVE-2025-29891). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.1. Users are recommended to upgrade to version 4.19.0, which fixes the issue. If users are on the 4.18.x LTS releases stream, then they are suggested to upgrade to 4.18.1. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35384 • https://github.com/oscerd/CVE-2026-33454 #dbugs_vuln

    Post summary

    A proof‑of‑concept/exploit for Apache Camel's message‑header injection in the Camel‑Mail component has been released, along with clear patch guidance to upgrade to 4.19.0.

    020952.1K
    3.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple RCE vulnerabilities in Apache Camel components (CVE-2026-33453 / CVE-2026-33454 / CVE-2026-40453) CVE-2026-33453 - camel-coap allows header injection via URI query params, enabling unauthenticated RCE when routed to header-sensitive components (e.g. camel-exec). 👉 Affected: >= 4.14.0, <= 4.14.5 | >= 4.18.0, < 4.18.1 | 4.19.0 | Upgrade: 4.18.1 / 4.19.0 CVE-2026-33454 - camel-mail missing inbound header filtering allows attacker-controlled email headers to manipulate routes and trigger RCE in downstream components. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.1 | Upgrade: 4.14.6 / 4.18.1 / 4.19.0 CVE-2026-40453 - Multiple components lack case-insensitive header filtering, enabling injection of Camel internal headers and leading to RCE/file write via downstream processors. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.2 | >= 4.19.0, < 4.20.0 | Upgrade: 4.14.6 / 4.18.2 / 4.20.0

    Post summary

    The post announces three critical RCE CVEs in Apache Camel components, detailing the injection vectors, affected versions, and upgrade guidance to mitigate the issue.

    00040107
    237 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical RCE in #Apache #Camel via email! #CVE-2026-33454 CVSS: 9.4. A crafted email can smuggle instructions into your flow → remote code execution. #RCE Read our advisory: https://ccb.belgium.be/advisories/warning-critical-apache-camel-vulnerability-allows-remote-code-execution-email-patch #Patch #Patch #Patch

    Post summary

    The message announces a critical RCE in Apache Camel (CVE‑2026‑33454) triggered via crafted emails, provides key technical details, and points to an advisory that includes a patch.

    02000397
    7.2K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-33454: A PoC has been released for an Apache Camel vulnerability that could allow message header injection, potentially impacting downstream components. Users should upgrade to 4.19.0 or the latest supported LTS release. 🔗 https://github.com/oscerd/CVE-2026-33454 #CyberSecurity

    Post summary

    A proof‑of‑concept for CVE-2026-33454, an Apache Camel message header injection flaw, has been made available, and users are advised to upgrade to the latest LTS release.

    0101070
    65 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    Today — CVE-2026-33454, camel-mail, CVSS 9.4. A crafted email arrives at a camel-mail consumer, the mail headers get stamped onto the Exchange object, same downstream components, same RCE outcome. https://nvd.nist.gov/vuln/detail/CVE-2026-33454

    Post summary

    A newly disclosed CVE-2026-33454 in camel-mail allows remote code execution through crafted email headers, with a CVSS score of 9.4.

    1000028
    34 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    アパッチ・キャメルの脆弱性の要点と対策を解説。今すぐチェック 【脆弱性情報】 CVE-2026-33454 apacheのcamelの脆弱性について https://www.cybernote.click/2026/05/02/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-33454-apache%e3%81%aecamel%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-33454-apache%25e3%2581%25aecamel%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post announces CVE‑2026‑33454 for Apache Camel and directs readers to a blog for more information, but it provides no technical details, exploit code, or patch information.

    0000077
    211 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filt… https://www.cve.org/CVERecord?id=CVE-2026-33454

    Post summary

    CVE-2026-33454 is an injection vulnerability in the Camel-Mail component; the notice provides technical details but no PoC, exploit, or patch information.

    00000217
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33454 CVE-2026-33454 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33454

    Post summary

    The text merely lists CVE‑2026‑33454 and a link to a vulnerability database entry, providing no additional technical or situational details.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more