{"id":"GHSA-46jf-c9vx-hh79","summary":"Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input","details":"Improper Input Validation vulnerability in Apache Camel.\n\nThis issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.\n\nUsers are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.","aliases":["CVE-2026-46587"],"modified":"2026-08-28T19:55:41.237201Z","published":"2026-07-06T12:31:30Z","database_specific":{"github_reviewed_at":"2026-08-28T19:34:04Z","nvd_published_at":"2026-07-06T11:16:28Z","cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46587"},{"type":"WEB","url":"https://github.com/apache/camel/pull/23228"},{"type":"WEB","url":"https://github.com/apache/camel/pull/23230"},{"type":"WEB","url":"https://github.com/apache/camel/pull/23231"},{"type":"WEB","url":"https://github.com/apache/camel/commit/8d74cdca9befc74b49d9c52ac6a145be1d413e7d"},{"type":"WEB","url":"https://github.com/apache/camel/commit/c16f7ef39849ae8819f50c959b538350b8f839e9"},{"type":"WEB","url":"https://github.com/apache/camel/commit/d0dfa4e0ebd062acaf4a86ca476bb4305db9bfd4"},{"type":"WEB","url":"https://camel.apache.org/security/CVE-2026-46587.html"},{"type":"PACKAGE","url":"https://github.com/apache/camel"},{"type":"WEB","url":"https://github.com/apache/camel/releases/tag/camel-4.14.8"},{"type":"WEB","url":"https://github.com/apache/camel/releases/tag/camel-4.18.3"},{"type":"WEB","url":"https://github.com/apache/camel/releases/tag/camel-4.21.0"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/06/15"}],"affected":[{"package":{"name":"org.apache.camel:camel-couchbase","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-couchbase"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.14.8"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.1.0","4.10.0","4.10.1","4.10.2","4.10.3","4.10.4","4.10.5","4.10.6","4.10.7","4.10.8","4.10.9","4.11.0","4.12.0","4.13.0","4.14.0","4.14.1","4.14.2","4.14.3","4.14.4","4.14.5","4.14.6","4.14.7","4.2.0","4.3.0","4.4.0","4.4.1","4.4.2","4.4.3","4.4.4","4.4.5","4.5.0","4.6.0","4.7.0","4.8.0","4.8.1","4.8.2","4.8.3","4.8.4","4.8.5","4.8.6","4.8.7","4.8.8","4.8.9","4.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46jf-c9vx-hh79/GHSA-46jf-c9vx-hh79.json"}},{"package":{"name":"org.apache.camel:camel-couchbase","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-couchbase"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.18.3"}]}],"versions":["4.15.0","4.16.0","4.17.0","4.18.0","4.18.1","4.18.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46jf-c9vx-hh79/GHSA-46jf-c9vx-hh79.json"}},{"package":{"name":"org.apache.camel:camel-couchbase","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-couchbase"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"4.21.0"}]}],"versions":["4.19.0","4.20.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46jf-c9vx-hh79/GHSA-46jf-c9vx-hh79.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}