CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel: Couchbaseto a version that resolves this vulnerability.Fixed in 4.14.8 - Upgrade
Upgrade
Apache Camel: Couchbaseto a version that resolves this vulnerability.Fixed in 4.18.3 - Upgrade
Upgrade
Apache Camel: Couchbaseto a version that resolves this vulnerability.Fixed in 4.21.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46587?
The severity of CVE-2026-46587 is rated as 57, indicating a moderate risk level.
How do I fix CVE-2026-46587?
To fix CVE-2026-46587, users should upgrade to Apache Camel version 4.14.8, 4.18.3, or 4.21.0.
What systems are affected by CVE-2026-46587?
CVE-2026-46587 affects Apache Camel versions from 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0.
What type of vulnerability is CVE-2026-46587?
CVE-2026-46587 is categorized as an Improper Input Validation vulnerability.
What can happen if CVE-2026-46587 is exploited?
If exploited, CVE-2026-46587 allows untrusted input to bypass the HeaderFilterStrategy and potentially override operations in Apache Camel.