HIGH7.3
GHSA-46jf-c9vx-hh79
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Quick fix
GHSA-46jf-c9vx-hh79 — org.apache.camel:camel-couchbase: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.14.8</version> for org.apache.camel:camel-couchbaseDetails
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.camel:camel-couchbase
Introduced in:
4.0.0Fixed in: 4.14.8Fix
# pom.xml: bump <version>4.14.8</version> for org.apache.camel:camel-couchbaseMaven/org.apache.camel:camel-couchbase
Introduced in:
4.15.0Fixed in: 4.18.3Fix
# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-couchbaseMaven/org.apache.camel:camel-couchbase
Introduced in:
4.19.0Fixed in: 4.21.0Fix
# pom.xml: bump <version>4.21.0</version> for org.apache.camel:camel-couchbaseReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-46587[ADVISORY]
- https://github.com/apache/camel/pull/23228[WEB]
- https://github.com/apache/camel/pull/23230[WEB]
- https://github.com/apache/camel/pull/23231[WEB]
- https://github.com/apache/camel/commit/8d74cdca9befc74b49d9c52ac6a145be1d413e7d[WEB]
- https://github.com/apache/camel/commit/c16f7ef39849ae8819f50c959b538350b8f839e9[WEB]
- https://github.com/apache/camel/commit/d0dfa4e0ebd062acaf4a86ca476bb4305db9bfd4[WEB]
- https://camel.apache.org/security/CVE-2026-46587.html[WEB]
- https://github.com/apache/camel[PACKAGE]
- https://github.com/apache/camel/releases/tag/camel-4.14.8[WEB]
- https://github.com/apache/camel/releases/tag/camel-4.18.3[WEB]
- https://github.com/apache/camel/releases/tag/camel-4.21.0[WEB]
- http://www.openwall.com/lists/oss-security/2026/07/06/15[WEB]