CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Published Jul 6, 2026
·Updated
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
Affected Software
4 affected components
Apache Camel>=4.14.0<4.14.8, >=4.15.0<=4.18.2, >=4.19.0<=4.20.0, >=4.21.0<4.21.0
Apache Camel>=4.0.0<4.14.8
Apache Camel>=4.15.0<4.18.3
Apache Camel>=4.19.0<4.21.0
Remediation
Patch Available
Event History
Jul 6, 2026
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46588?
CVE-2026-46588 has a risk score of 52, indicating a moderate level of severity.
2
How do I fix CVE-2026-46588?
To fix CVE-2026-46588, upgrade to Apache Camel versions 4.14.8, 4.18.3, or 4.21.0.
3
What is the impact of CVE-2026-46588 on Apache Camel?
CVE-2026-46588 allows an operation override from untrusted input due to improper input validation in CouchDB.
4
Which versions of Apache Camel are affected by CVE-2026-46588?
CVE-2026-46588 affects Apache Camel versions through 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0.
5
What type of vulnerability is CVE-2026-46588 classified as?
CVE-2026-46588 is classified as an Improper Input Validation vulnerability.