AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-40453.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilterStrategy in camel-sjms, CoAPHeaderFilterStrategy in camel-coap, and GooglePubsubHeaderFilterStrategy in camel-google-pubsub. Because those strategies use case-sensitive String.startsWith('Camel'/'camel') filtering while the Camel Exchange stores headers in a case-insensitive map, an attacker with JMS (or equivalent) producer access to the broker consumed by a Camel route can inject case-variant Camel internal headers, which are then resolved by downstream components such as camel-exec and camel-file using their canonical casing. This enables remote code execution and arbitrary file write on routes that forward JMS messages to header-driven components. This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to u

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-jg2m-9x48-3gvj

Open original source · Updated Oct 05, 2026

Apache Camel has an incomplete fix for CVE-2025-27636

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
mavenorg.apache.camel:camel-coap>= 3.0.0, < 4.14.64.14.6
mavenorg.apache.camel:camel-coap>= 4.15.0, < 4.18.24.18.2
mavenorg.apache.camel:camel-coap>= 4.19.0, < 4.20.04.20.0
mavenorg.apache.camel:camel-google-pubsub>= 3.0.0, < 4.14.64.14.6
mavenorg.apache.camel:camel-google-pubsub>= 4.15.0, < 4.18.24.18.2
mavenorg.apache.camel:camel-google-pubsub>= 4.19.0, < 4.20.04.20.0
mavenorg.apache.camel:camel-jms>= 3.0.0, < 4.14.64.14.6
mavenorg.apache.camel:camel-jms>= 4.15.0, < 4.18.24.18.2
mavenorg.apache.camel:camel-jms>= 4.19.0, < 4.20.04.20.0
mavenorg.apache.camel:camel-sjms>= 3.0.0, < 4.14.64.14.6
mavenorg.apache.camel:camel-sjms>= 4.15.0, < 4.18.24.18.2
mavenorg.apache.camel:camel-sjms>= 4.19.0, < 4.20.04.20.0

Original records & references

PUBLISHED 2026-04-27T05:34:39-04:00
MODIFIED 2026-10-05T14:38:51-04:00
INGESTED 2026-10-06T11:45:33-04:00