CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
Published Jul 6, 2026
·Updated
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.
Affected Software
3 affected components
Apache Camel>=4.8.0<=4.18.2, >=4.19.0<=4.20.0
Apache Camel>=4.8.0<4.18.3
Apache Camel>=4.19.0<4.21.0
Remediation
Patch Available
Event History
Jul 6, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49042?
CVE-2026-49042 has a risk rating of 37, indicating a significant security concern.
2
How do I fix CVE-2026-49042?
To fix CVE-2026-49042, upgrade Apache Camel to version 4.18.3 or 4.21.0.
3
What versions of Apache Camel are affected by CVE-2026-49042?
CVE-2026-49042 affects Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0.
4
What type of vulnerability is CVE-2026-49042?
CVE-2026-49042 is classified as an Improper Input Validation vulnerability.
5
When was CVE-2026-49042 published?
CVE-2026-49042 was published on July 6, 2026.