CVEFinder.io

CVE-2025-29891

πŸ”Ά medium
πŸ” Scan for this CVE
Summary

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component,

Description

Bypass/Injection vulnerability in Apache Camel.

This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4.

Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.

This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, or the camel-exec component.

If you have Camel applications that are directly connected to the internet via HTTP, then an attackerΒ could include parameters in the HTTP requests that are sent to the Camel application that get translated into headers.Β 

The headers could be both provided as request parameters for an HTTP methods invocation or as part of the payload of the HTTP methods invocation.

All the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box.

This CVE is related to the CVE-2025-27636: while they have the same root cause and are fixed with the same fix, CVE-2025-27636 was assumed to only be exploitable if an attacker could add malicious HTTP headers, while we have now determined that it is also exploitable via HTTP parameters. Like in CVE-2025-27636, exploitation is only possible if the Camel route uses particular vulnerable components.

CVSS Score
4.8
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2025-03-12
First Seen: 2026-01-05
πŸ“Š Relative Risk Intelligence

This CVE is Lower Risk - more severe than 13.8% of all 330,193 vulnerabilities in our database.

#284,724
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Mar 19, 2025
πŸ” Exploitation Status
Poc
Proof-of-concept available
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Partial
Limited system impact
πŸ† Discovered By
Citi Cyber Security Operations Akamai Security Intelligence Group (SIG) (reporter) Mark Thorson of AT&T Mark Thorson of AT&T (reporter)
SSVC data provided by CISA
Last Modified 2025-04-02
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 3

πŸ”— References 3

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-47323 β›” critical 9.8 0.1 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra... 2026-05-19
CVE-2026-23552 β›” critical 9.1 0.0 Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.Β  The Camel-Keycloak Key... 2026-02-23
CVE-2026-25747 ⚠️ high 8.8 0.1 Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSeri... 2026-02-23
CVE-2025-66169 πŸ”Ά medium 5.3 0.2 Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo... 2026-01-14
CVE-2025-30177 πŸ”Ά medium 6.5 0.6 Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affe... 2025-04-01
CVE-2025-27636 πŸ”Ά medium 5.6 28.4 Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel:... 2025-03-09
These CVEs affect the same products