
🚨 Critical - Multiple RCE vulnerabilities in Apache Camel components (CVE-2026-33453 / CVE-2026-33454 / CVE-2026-40453) CVE-2026-33453 - camel-coap allows header injection via URI query params, enabling unauthenticated RCE when routed to header-sensitive components (e.g. camel-exec). 👉 Affected: >= 4.14.0, <= 4.14.5 | >= 4.18.0, < 4.18.1 | 4.19.0 | Upgrade: 4.18.1 / 4.19.0 CVE-2026-33454 - camel-mail missing inbound header filtering allows attacker-controlled email headers to manipulate routes and trigger RCE in downstream components. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.1 | Upgrade: 4.14.6 / 4.18.1 / 4.19.0 CVE-2026-40453 - Multiple components lack case-insensitive header filtering, enabling injection of Camel internal headers and leading to RCE/file write via downstream processors. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.2 | >= 4.19.0, < 4.20.0 | Upgrade: 4.14.6 / 4.18.2 / 4.20.0
Post summary
The post announces three Apache Camel component RCE vulnerabilities, detailing affected versions, technical exploitation vectors, and provides recommended upgrade paths.




