CVE-2026-78329: CWE-20 Improper input validation in Apache Software Foundation Apache Camel
CVE-2026-78329 is an improper input validation vulnerability in the Apache Camel Undertow component affecting versions from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, and from 4.19.0 before 4.22.0. The issue arises because the UndertowEndpoint overwrites its headerFilterStrategy with a base strategy that does not apply undertow-specific filtering, allowing legacy websocket. Exchange-header prefixed headers to bypass filtering. This can cause headers to be mapped incorrectly, potentially allowing a WebSocket producer to deliver messages to unintended peers. The vulnerability does not affect Rest DSL consumers and is not a regression of a previous CVE. Users are recommended to upgrade to fixed versions or apply explicit headerFilterStrategy configuration and header stripping as a workaround. The fix restores filtering at the transport boundary but does not protect routes that carry untrusted messages from non-undertow consumers into undertow producers.
AI Analysis
Technical Summary
This vulnerability in Apache Camel's Undertow component involves improper input validation due to the default headerFilterStrategy being overwritten with a base strategy that lacks undertow-specific filtering. As a result, legacy websocket. Exchange-header prefixed headers are not filtered at the transport boundary, allowing them to be mapped onto the Exchange and potentially misdirected by the WebSocket producer. The flaw affects versions >=4.11.0 <4.14.9, >=4.15.0 <4.18.4, and >=4.19.0 <4.22.0. The issue is fixed in versions 4.14.9, 4.18.4, and 4.22.0. Workarounds include explicitly configuring the headerFilterStrategy and removing websocket.* headers at the trust boundary. The fix provides defense in depth at the transport boundary but does not fully protect routes with untrusted messages from non-undertow consumers.
Potential Impact
The vulnerability allows legacy websocket. Exchange-header prefixed headers to bypass filtering at the Undertow transport boundary, potentially enabling a WebSocket producer to deliver messages to unintended peers. This could lead to message misrouting or unauthorized message dispatch within affected Apache Camel routes. Rest DSL consumers are not affected. The impact is limited to scenarios where the default headerFilterStrategy is used and untrusted headers are present. There is no indication of active exploitation in the wild.
Mitigation Recommendations
Users should upgrade to Apache Camel versions 4.14.9, 4.18.4, or 4.22.0 where this issue is fixed. For those unable to upgrade immediately, explicitly configure the UndertowHeaderFilterStrategy by binding it in the registry and referencing it on the endpoint. Additionally, remove websocket.* headers at the trust boundary using removeHeaders("websocket.*"). Note that the fix only restores filtering at the Undertow transport boundary; routes carrying untrusted messages from non-Undertow consumers into Undertow producers must implement their own header stripping to ensure protection.
CVE-2026-78329: CWE-20 Improper input validation in Apache Software Foundation Apache Camel
Description
CVE-2026-78329 is an improper input validation vulnerability in the Apache Camel Undertow component affecting versions from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, and from 4.19.0 before 4.22.0. The issue arises because the UndertowEndpoint overwrites its headerFilterStrategy with a base strategy that does not apply undertow-specific filtering, allowing legacy websocket. Exchange-header prefixed headers to bypass filtering. This can cause headers to be mapped incorrectly, potentially allowing a WebSocket producer to deliver messages to unintended peers. The vulnerability does not affect Rest DSL consumers and is not a regression of a previous CVE. Users are recommended to upgrade to fixed versions or apply explicit headerFilterStrategy configuration and header stripping as a workaround. The fix restores filtering at the transport boundary but does not protect routes that carry untrusted messages from non-undertow consumers into undertow producers.
Affected software
pkg:maven/Apache Software Foundation/org.apache.camel:camel-undertowRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Apache Camel's Undertow component involves improper input validation due to the default headerFilterStrategy being overwritten with a base strategy that lacks undertow-specific filtering. As a result, legacy websocket. Exchange-header prefixed headers are not filtered at the transport boundary, allowing them to be mapped onto the Exchange and potentially misdirected by the WebSocket producer. The flaw affects versions >=4.11.0 <4.14.9, >=4.15.0 <4.18.4, and >=4.19.0 <4.22.0. The issue is fixed in versions 4.14.9, 4.18.4, and 4.22.0. Workarounds include explicitly configuring the headerFilterStrategy and removing websocket.* headers at the trust boundary. The fix provides defense in depth at the transport boundary but does not fully protect routes with untrusted messages from non-undertow consumers.
Potential Impact
The vulnerability allows legacy websocket. Exchange-header prefixed headers to bypass filtering at the Undertow transport boundary, potentially enabling a WebSocket producer to deliver messages to unintended peers. This could lead to message misrouting or unauthorized message dispatch within affected Apache Camel routes. Rest DSL consumers are not affected. The impact is limited to scenarios where the default headerFilterStrategy is used and untrusted headers are present. There is no indication of active exploitation in the wild.
Mitigation Recommendations
Users should upgrade to Apache Camel versions 4.14.9, 4.18.4, or 4.22.0 where this issue is fixed. For those unable to upgrade immediately, explicitly configure the UndertowHeaderFilterStrategy by binding it in the registry and referencing it on the endpoint. Additionally, remove websocket.* headers at the trust boundary using removeHeaders("websocket.*"). Note that the fix only restores filtering at the Undertow transport boundary; routes carrying untrusted messages from non-Undertow consumers into Undertow producers must implement their own header stripping to ensure protection.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-24T09:47:36.708Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8c76e0acd9273b49d9f01d
Added to database: 08/24/2026, 16:52:48 UTC
Last enriched: 08/24/2026, 17:07:40 UTC
Last updated: 08/24/2026, 17:15:21 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.