CVE-2025-27636 is a bypass/injection vulnerability in Apache Camel's default incoming header filter, affecting versions 4.10.0-4.10.1, 4.8.0-4.8.4, and 3.10.0-3.22.3. This flaw allows attackers to inject malicious Camel-specific headers, potentially altering component behavior such as invoking unintended methods or redirecting messages, especially in applications exposed via HTTP. Rated Medium (CVSS 5.6), the vulnerability has a network attack vector with high complexity, requiring no privileges or user interaction, and results in low impacts to confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code (PoC) is publicly available on GitHub, and the vulnerability is actively discussed within the cybersecurity community, indicating elevated risk. Users are advised to upgrade to patched versions 4.10.2, 4.8.5, or 3.22.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.10.0, < 3.22.4CPE matchmatch criteria | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | ||
>= 4.8.0, < 4.8.5CPE matchmatch criteria | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.2CPE matchmatch criteria | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2026-40453: Apache Camel: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
Apr 26, 2026camel-http: org.apache.camel: bypass of header filters via specially crafted response
Mar 10, 2025Apache Camel: Camel Message Header Injection via Improper Filtering
Mar 9, 2025