https://seclists.org/oss-sec/2026/q3/44: CVE-2026-48203: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header pfixes used non-Camel-pfixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side quest forgery) and document fields
Published Jul 5, 2026
·Updated
Affected Software
1 affected component
Apache Apache Camel>4.0.0<=4.14.8, >4.15.0<=4.18.3, >4.19.0<=4.21.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48203?
The severity of CVE-2026-48203 is considered moderate.
2
How do I fix CVE-2026-48203?
To fix CVE-2026-48203, upgrade to Apache Camel versions 4.14.8, 4.18.3, or 4.21.0 or later.
3
What versions of Apache Camel are affected by CVE-2026-48203?
Apache Camel versions 4.0.0 before 4.14.8, 4.15.0 before 4.18.3, and 4.19.0 before 4.21.0 are affected by CVE-2026-48203.
4
What does CVE-2026-48203 exploit in Apache Camel?
CVE-2026-48203 exploits improper neutralization of special elements in output, allowing HTTP clients to inject Solr query parameters.
5
What impact does CVE-2026-48203 have on applications using Apache Camel?
CVE-2026-48203 can lead to server-side request forgery (SSRF) vulnerabilities for applications using the impacted versions of Apache Camel.