https://seclists.org/oss-sec/2026/q3/73: CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-pfixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Apache Camel<=4.14.7, >=4.15.0<=4.18.2, >=4.19.0<=4.20.0
Frequently Asked Questions
1
What is the severity of CVE-2026-46588?
The severity of CVE-2026-46588 is classified as important.
2
Which versions of Apache Camel are affected by CVE-2026-46588?
CVE-2026-46588 affects Apache Camel through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0.
3
How do I fix CVE-2026-46588?
To fix CVE-2026-46588, you should upgrade to Apache Camel version 4.20.1 or later.
4
What type of vulnerability is CVE-2026-46588?
CVE-2026-46588 is classified as an Improper Input Validation vulnerability.
5
What is the impact of CVE-2026-46588 on Apache Camel?
The impact of CVE-2026-46588 is that it allows untrusted input to bypass the HeaderFilterStrategy, potentially overriding operations.