CVE-2026-40453General(apache / camel)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilterStrategy in camel-sjms, CoAPHeaderFilterStrategy in camel-coap, and GooglePubsubHeaderFilterStrategy in camel-google-pubsub. Because those strategies use case-sensitive String.startsWith('Camel'/'camel') filtering while the Camel Exchange stores headers in a case-insensitive map, an attacker with JMS (or equivalent) producer access to the broker consumed by a Camel route can inject case-variant Camel internal headers, which are then resolved by downstream components such as camel-exec and camel-file using their canonical casing. This enables remote code execution and arbitrary file write on routes that forward JMS messages to header-driven components. This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-10)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-10: 2Exploit Tool / Code · 2026-07-10: 2Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-04-28: 1Technical Details · 2026-07-10: 204-2604-2704-2807-10
Signal classification3 categories
General
240.0%
PoC
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-271
General1
2026-04-281
Disclosure1
2026-07-102
PoC2
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple RCE vulnerabilities in Apache Camel components (CVE-2026-33453 / CVE-2026-33454 / CVE-2026-40453) CVE-2026-33453 - camel-coap allows header injection via URI query params, enabling unauthenticated RCE when routed to header-sensitive components (e.g. camel-exec). 👉 Affected: >= 4.14.0, <= 4.14.5 | >= 4.18.0, < 4.18.1 | 4.19.0 | Upgrade: 4.18.1 / 4.19.0 CVE-2026-33454 - camel-mail missing inbound header filtering allows attacker-controlled email headers to manipulate routes and trigger RCE in downstream components. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.1 | Upgrade: 4.14.6 / 4.18.1 / 4.19.0 CVE-2026-40453 - Multiple components lack case-insensitive header filtering, enabling injection of Camel internal headers and leading to RCE/file write via downstream processors. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.2 | >= 4.19.0, < 4.20.0 | Upgrade: 4.14.6 / 4.18.2 / 4.20.0

    Post summary

    The post announces three Apache Camel component RCE vulnerabilities, detailing affected versions, technical exploitation vectors, and provides recommended upgrade paths.

    00040107
    237 followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-40453: A PoC has been released for an Apache Camel JMS vulnerability that could lead to remote code execution (RCE) through case-variant header injection. Upgrade to a patched release. 🔗 https://github.com/oscerd/CVE-2026-40453 #CyberSecurity #CVE #Apache #Camel #RCE #ThreatWire

    Post summary

    A proof-of-concept demonstrating remote code execution via case-variant header injection in Apache Camel JMS has been released, and users are urged to upgrade to a patched version.

    0001083
    69 followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-40453 PT ID: PT-2026-35370 Vendor: Apache Software Foundation Product: Apache Camel JMS Description: The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilterStrategy in camel-sjms, CoAPHeaderFilterStrategy in camel-coap, and GooglePubsubHeaderFilterStrategy in camel-google-pubsub. Because those strategies use case-sensitive String.startsWith('Camel'/'camel') filtering while the Camel Exchange stores headers in a case-insensitive map, an attacker with JMS (or equivalent) producer access to the broker consumed by a Camel route can inject case-variant Camel internal headers, which are then resolved by downstream components such as camel-exec and camel-file using their canonical casing. This enables remote code execution and arbitrary file write on routes that forward JMS messages to header-driven components. This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35370 • https://github.com/oscerd/CVE-2026-40453 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑40453 has been released, demonstrating remote code execution via case‑variant JMS header injection. The post details the vulnerability mechanism and provides access to the PoC code.

    00010643
    2.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40453 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered ou… https://www.cve.org/CVERecord?id=CVE-2026-40453

    Post summary

    The snippet references CVE-2026-40453 with a link but provides only a vague mention of a related fix for another CVE, lacking substantive technical or exploit details.

    00000341
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40453 CVE-2026-40453 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40453

    Post summary

    The post merely repeats the CVE identifier and links to a vulnerability details page, providing no actionable information about exploitation, patches, or technical details.

    0000050
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.19.0--

Explore more