CVE-2026-46587

CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

Vendor Apache Software Foundation
Product Apache Camel
Weakness CWE-20 · Input validation
Published July 6, 2026
Last update July 6, 2026

CVSS base score

What the vulnerability does

01Description

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.

Key dates

02Disclosure timeline

July 6, 2026 CVE published
July 6, 2026 Record updated

Related vulnerabilities

04Related CVE