Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-78329: CWE-20 Improper input validation in Apache Software Foundation Apache Camel

0
Medium
VulnerabilityCVE-2026-78329cvecve-2026-78329cwe-20
Published: 08/24/2026 (08/24/2026, 16:22:17 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Camel

Description

CVE-2026-78329 is an improper input validation vulnerability in the Apache Camel Undertow component affecting versions from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, and from 4.19.0 before 4.22.0. The issue arises because the UndertowEndpoint overwrites its headerFilterStrategy with a base strategy that does not apply undertow-specific filtering, allowing legacy websocket. Exchange-header prefixed headers to bypass filtering. This can cause headers to be mapped incorrectly, potentially allowing a WebSocket producer to deliver messages to unintended peers. The vulnerability does not affect Rest DSL consumers and is not a regression of a previous CVE. Users are recommended to upgrade to fixed versions or apply explicit headerFilterStrategy configuration and header stripping as a workaround. The fix restores filtering at the transport boundary but does not protect routes that carry untrusted messages from non-undertow consumers into undertow producers.

Affected software

Apache Software Foundation/org.apache.camel:camel-undertow
pkg:maven/Apache Software Foundation/org.apache.camel:camel-undertow
Affected versions
>=4.11.0 <4.14.9>=4.15.0 <4.18.4>=4.19.0 <4.22.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/24/2026, 17:07:40 UTC

Technical Analysis

This vulnerability in Apache Camel's Undertow component involves improper input validation due to the default headerFilterStrategy being overwritten with a base strategy that lacks undertow-specific filtering. As a result, legacy websocket. Exchange-header prefixed headers are not filtered at the transport boundary, allowing them to be mapped onto the Exchange and potentially misdirected by the WebSocket producer. The flaw affects versions >=4.11.0 <4.14.9, >=4.15.0 <4.18.4, and >=4.19.0 <4.22.0. The issue is fixed in versions 4.14.9, 4.18.4, and 4.22.0. Workarounds include explicitly configuring the headerFilterStrategy and removing websocket.* headers at the trust boundary. The fix provides defense in depth at the transport boundary but does not fully protect routes with untrusted messages from non-undertow consumers.

Potential Impact

The vulnerability allows legacy websocket. Exchange-header prefixed headers to bypass filtering at the Undertow transport boundary, potentially enabling a WebSocket producer to deliver messages to unintended peers. This could lead to message misrouting or unauthorized message dispatch within affected Apache Camel routes. Rest DSL consumers are not affected. The impact is limited to scenarios where the default headerFilterStrategy is used and untrusted headers are present. There is no indication of active exploitation in the wild.

Mitigation Recommendations

Users should upgrade to Apache Camel versions 4.14.9, 4.18.4, or 4.22.0 where this issue is fixed. For those unable to upgrade immediately, explicitly configure the UndertowHeaderFilterStrategy by binding it in the registry and referencing it on the endpoint. Additionally, remove websocket.* headers at the trust boundary using removeHeaders("websocket.*"). Note that the fix only restores filtering at the Undertow transport boundary; routes carrying untrusted messages from non-Undertow consumers into Undertow producers must implement their own header stripping to ensure protection.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-24T09:47:36.708Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a8c76e0acd9273b49d9f01d

Added to database: 08/24/2026, 16:52:48 UTC

Last enriched: 08/24/2026, 17:07:40 UTC

Last updated: 08/24/2026, 17:15:21 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses