CVE-2025-30177 is a bypass/injection vulnerability in the Apache Camel Camel-Undertow component, affecting versions 4.10.0 through 4.10.2 and 4.8.0 through 4.8.5. This flaw allows attackers to inject Camel-specific headers due to an insufficient header filtering strategy, potentially altering the behavior of other Camel components like camel-bean or camel-exec. Rated Medium severity (CVSS 6.5), it has a low attack complexity and can lead to partial confidentiality and integrity impacts without requiring user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.8.0, < 4.8.6CPE matchmatch criteria | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.3CPE matchmatch criteria | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2026-33454: Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
Apr 26, 2026Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability
Apr 1, 2025org.apache.camel/camel-undertow: Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering
Apr 1, 2025