Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-78329'

View all threats tagged with 'cve-2026-78329'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-78329

Threats Tagged 'cve-2026-78329'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-78329: CWE-20 Improper input validation in Apache Software Foundation Apache CamelCVE-2026-78329
0

CVE-2026-78329 is an improper input validation vulnerability in the Apache Camel Undertow component affecting versions from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, and from 4.19.0 before 4.22.0. The issue arises because the UndertowEndpoint overwrites its headerFilterStrategy with a base strategy that does not apply undertow-specific filtering, allowing legacy websocket. Exchange-header prefixed headers to bypass filtering. This can cause headers to be mapped incorrectly, potentially allowing a WebSocket producer to deliver messages to unintended peers. The vulnerability does not affect Rest DSL consumers and is not a regression of a previous CVE. Users are recommended to upgrade to fixed versions or apply explicit headerFilterStrategy configuration and header stripping as a workaround. The fix restores filtering at the transport boundary but does not protect routes that carry untrusted messages from non-undertow consumers into undertow producers.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2026-78329
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses