https://seclists.org/oss-sec/2026/q3/55: CVE-2026-55994: Apache Camel: Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side quest forgery and disclosuof sects when bridged
Published Jul 5, 2026
·Updated
Affected Software
2 affected components
Apache Camel camel-iggy>4.17.0<4.18.3
Apache Camel camel-iggy>4.19.0<4.21.0
Frequently Asked Questions
1
What is the severity of CVE-2026-55994?
The severity of CVE-2026-55994 is classified as important.
2
What versions of Apache Camel are affected by CVE-2026-55994?
CVE-2026-55994 affects Apache Camel (org.apache.camel:camel-iggy) versions 4.17.0 before 4.18.3 and 4.19.0 before 4.21.0.
3
How do I fix CVE-2026-55994?
To fix CVE-2026-55994, upgrade to Apache Camel (org.apache.camel:camel-iggy) version 4.18.3 or later for 4.17.x, and 4.21.0 or later for 4.19.x.
4
What kind of vulnerabilities does CVE-2026-55994 represent?
CVE-2026-55994 represents vulnerabilities including improper input validation, exposure of sensitive information, and server-side request forgery.
5
What are the potential impacts of CVE-2026-55994?
The potential impacts of CVE-2026-55994 include server-side request forgery and disclosure of sensitive information when bridged.