CVE-2025-27636
PoC ×3largeHeader Filter Bypass in Apache Camel Allows Bean Method and Queue Manipulation
CVE-2025-27636 is a case-sensitivity flaw (CWE-178) in the default incoming header filter of Apache Camel, which only blocks headers starting with "Camel", "camel", or "org.apache.camel.", allowing mixed-case variants such as "cAmel..." to pass through as trusted Camel runtime headers. An attacker who can inject custom headers into a Camel application — for example by sending crafted HTTP headers to applications exposed via camel-servlet, camel-jetty, camel-undertow, camel-platform-http, or camel-netty-http — can alter component behavior, such as making camel-bean invoke a different method on a bean than the application coded, or redirecting camel-jms messages to another queue on the same broker; similar behavior changes were observed with camel-exec. Depending on the components and methods in use, this can lead to information disclosure, integrity, or availability impact, and public proof-of-concept exploits (including demonstrations of remote code execution) already exist. Applications running Apache Camel 3.10.0 through 3.22.3, 4.8.0 through 4.8.4, or 4.10.0 through 4.10.1 that use the default header filter with any of the roughly two dozen listed components are affected, but practical exploitability requires attacker-reachable header injection, such as internet-facing HTTP endpoints. The flaw is not yet in CISA's KEV catalog, but public PoCs are available and EPSS puts the 30-day exploitation probability at 81.1% (100th percentile), so exploitation is considered likely.
What to do: Upgrade to Apache Camel 4.10.2 (4.10.x LTS), 4.8.5 (4.8.x LTS), or 3.22.4 (3.x). As an interim mitigation, add a removeHeaders EIP (globally or per route) to strip header names matching mixed-case variants of "camel" (e.g., "cAmel", "cAMEL") or anything not starting with "Camel", "camel", or "org.apache.camel.". Prioritize reviewing internet-facing routes that use camel-servlet, camel-jetty, camel-undertow, camel-platform-http, or camel-netty-http, especially those invoking camel-bean or routing camel-jms messages.
| Apache Camel | 3.10.0 through 3.22.3, 4.8.0 through 4.8.4, and 4.10.0 through 4.10.1 (components using the default header filter, including camel-activemq, camel-activemq6, ca |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, to call another method on the bean, than was coded in the application. In the camel-jms component, then a malicious header can be used to send the message to another queue (on the same broker) than was coded in the application. This could also be seen by using the camel-exec component The attacker would need to inject custom headers, such as HTTP protocols. So if you have Camel applications that are directly connected to the internet via HTTP, then an attacker could include malicious HTTP headers in the HTTP requests that are send to the Camel application. All the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box. In these conditions an attacker could be able to forge a Camel header name and make the bean component invoking other methods in the same bean. In terms of usage of the default header filter strategy the list of components using that is: * camel-activemq * camel-activemq6 * camel-amqp * camel-aws2-sqs * camel-azure-servicebus * camel-cxf-rest * camel-cxf-soap * camel-http * camel-jetty * camel-jms * camel-kafka * camel-knative * camel-mail * camel-nats * camel-netty-http * camel-platform-http * camel-rest * camel-sjms * camel-spring-rabbitmq * camel-stomp * camel-tahu * camel-undertow * camel-xmpp The vulnerability arises due to a bug in the default filtering mechanism that only blocks headers starting with "Camel", "camel", or "org.apache.camel.". Mitigation: You can easily work around this in your Camel applications by removing the headers in your Camel routes. There are many ways of doing this, also globally or per route. This means you could use the removeHeaders EIP, to filter out anything like "cAmel, cAMEL" etc, or in general everything not starting with "Camel", "camel" or "org.apache.camel.".
- Vendors
- apache
- Products
- camel
- Weakness
- CWE-178
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L