← Vulnerability feed

Vulnerability record · CVE-2025-27636 · published 9 March 2025

CVE-2025-27636: Apache Camel header filter bypass enables bean method and queue injection

Apache · Camel

Apache Camel's default incoming header filter only blocks header names starting with "Camel", "camel", or "org.apache.camel.", so an attacker can inject Camel-specific headers using alternate casing such as "cAmel". Those headers reach components like camel-bean and camel-jms, letting an attacker invoke a different method on a bean or redirect a message to a different queue than the application intended.

5.6 CVSS 3.1 Medium EPSS 97% · top 0.1% CWE-178 · CWE-178
5.6CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, to call another method on the bean, than was coded in the application. In the camel-jms component, then a malicious header can be used to send the message to another queue (on the same broker) than was coded in the application. This could also be seen by using the camel-exec component The attacker would need to inject custom headers, such as HTTP protocols. So if you have Camel applications that are directly connected to the internet via HTTP, then an attacker could include malicious HTTP headers in the HTTP requests that are send to the Camel application. All the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box. In these conditions an attacker could be able to forge a Camel header name and make the bean component invoking other methods in the same bean. In terms of usage of the default header filter strategy the list of components using that is: * camel-activemq * camel-activemq6 * camel-amqp * camel-aws2-sqs * camel-azure-servicebus * camel-cxf-rest * camel-cxf-soap * camel-http * camel-jetty * camel-jms * camel-kafka * camel-knative * camel-mail * camel-nats * camel-netty-http * camel-platform-http * camel-rest * camel-sjms * camel-spring-rabbitmq * camel-stomp * camel-tahu * camel-undertow * camel-xmpp The vulnerability arises due to a bug in the default filtering mechanism that only blocks headers starting with "Camel", "camel", or "org.apache.camel.".  Mitigation: You can easily work around this in your Camel applications by removing the headers in your Camel routes. There are many ways of doing this, also globally or per route. This means you could use the removeHeaders EIP, to filter out anything like "cAmel, cAMEL" etc, or in general everything not starting with "Camel", "camel" or "org.apache.camel.".

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable without authentication, has a public proof-of-concept, and carries a very high EPSS score despite a medium CVSS rating.

What it is

Apache Camel's default incoming header filter only blocks header names starting with "Camel", "camel", or "org.apache.camel.", so an attacker can inject Camel-specific headers using alternate casing such as "cAmel". Those headers reach components like camel-bean and camel-jms, letting an attacker invoke a different method on a bean or redirect a message to a different queue than the application intended.

Impact

An attacker can alter application behavior by invoking unintended bean methods or rerouting messages to other queues on the same broker, potentially exposing data or triggering unintended processing. The CVSS vector rates confidentiality, integrity, and availability impact as low.

Attack surface

Reachable over the network without authentication or user interaction (AV:N/AC:H/PR:N/UI:N) by sending crafted HTTP headers to a Camel application exposed via HTTP components such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, or camel-netty-http. The same header injection applies to other components using the default header filter strategy, including messaging and cloud connectors.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.81126 (99.6th percentile) and a public proof-of-concept repository exists, indicating active interest and likely exploitation attempts.

What to do

  • Upgrade to Apache Camel 4.10.2 (4.10.x LTS), 4.8.5 (4.8.x LTS), or 3.22.4 (3.x) as applicable.
  • Where immediate upgrade is not possible, use the removeHeaders EIP in Camel routes to strip any header not starting with the exact allowed prefixes, including case variants like "cAmel" and "cAMEL".
  • Apply the header filtering globally or per route, and review routes using camel-bean, camel-jms, camel-exec, and other components listed as using the default header filter strategy.
  • Restrict direct internet exposure of Camel HTTP endpoints and place a reverse proxy or gateway in front that normalizes or rejects unexpected Camel-style headers.

Detection

  • Inspect HTTP request logs for header names that case-vary from Camel prefixes, such as "cAmel", "cAMEL", or mixed-case variants of org.apache.camel.
  • Monitor Camel application logs for unexpected bean method invocations or messages appearing on queues not targeted by the application logic.
  • Alert on JMS or messaging broker activity where message destinations differ from the configured route destinations.
  • Use network or WAF rules to flag requests containing headers matching case-insensitive patterns for Camel, org.apache.camel, or unusual header casing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-33453Apache camel mass assignment vulnerabilityImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's cam…EPSS 7.2%9.9CVE-2026-40453Apache camel vulnerabilityThe fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable…EPSS 1.9%9.8CVE-2026-80352Apache camel code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configur…EPSS 0.84%9.8CVE-2026-80351Apache camel vulnerabilityImproper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of…EPSS 1.0%9.8CVE-2026-78329Apache camel improper input validation vulnerabilityImproper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 b…EPSS 0.74%9.8CVE-2026-71300Apache camel improper input validation vulnerabilityImproper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, fr…EPSS 0.74%9.8CVE-2026-56140Apache camel improper input validation vulnerabilityImproper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-spe…EPSS 0.74%9.8CVE-2026-53913Apache camel improper authentication vulnerabilityImproper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-27636), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.