https://seclists.org/oss-sec/2026/q3/72: CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-pfixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Apache Apache Camel>4.14.7<4.14.8, >=4.15.0<=4.18.2, >=4.19.0<=4.20.0, >4.20.0<4.20.1
Frequently Asked Questions
1
What is the severity of CVE-2026-46587?
The severity of CVE-2026-46587 is classified as important.
2
Which versions of Apache Camel are affected by CVE-2026-46587?
CVE-2026-46587 affects Apache Camel versions through 4.14.7 and from 4.15.0 to 4.18.2, as well as from 4.19.0 to 4.20.0.
3
How do I fix CVE-2026-46587?
To fix CVE-2026-46587, upgrade to a version of Apache Camel that is not vulnerable, specifically versions higher than 4.20.0.
4
What type of vulnerability is CVE-2026-46587?
CVE-2026-46587 is categorized as an Improper Input Validation vulnerability.
5
What is the impact of CVE-2026-46587?
The impact of CVE-2026-46587 is that it allows operation override from untrusted input due to bypassing the HeaderFilterStrategy.