HIGH7.3
GHSA-hh8r-75r6-qrg9
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
Quick fix
GHSA-hh8r-75r6-qrg9 — org.apache.camel:camel-langchain4j-tools: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-langchain4j-toolsDetails
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0.
Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.camel:camel-langchain4j-tools
Introduced in:
4.8.0Fixed in: 4.18.3Fix
# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-langchain4j-toolsMaven/org.apache.camel:camel-langchain4j-tools
Introduced in:
4.19.0Fixed in: 4.21.0Fix
# pom.xml: bump <version>4.21.0</version> for org.apache.camel:camel-langchain4j-toolsMaven/org.apache.camel:camel-langchain4j-agent
Introduced in:
4.8.0Fixed in: 4.18.3Fix
# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-langchain4j-agentMaven/org.apache.camel:camel-langchain4j-agent
Introduced in:
4.19.0Fixed in: 4.21.0Fix
# pom.xml: bump <version>4.21.0</version> for org.apache.camel:camel-langchain4j-agentMaven/org.apache.camel:camel-spring-ai-tools
Introduced in:
4.8.0Fixed in: 4.18.3Fix
# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-spring-ai-toolsMaven/org.apache.camel:camel-spring-ai-tools
Introduced in:
4.19.0Fixed in: 4.21.0Fix
# pom.xml: bump <version>4.21.0</version> for org.apache.camel:camel-spring-ai-toolsReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-49042[ADVISORY]
- https://github.com/apache/camel/pull/23535[WEB]
- https://github.com/apache/camel/pull/23551[WEB]
- https://github.com/apache/camel/commit/5d0028f6bc7a70556dc1d408b1b6cadb59e1842d[WEB]
- https://github.com/apache/camel/commit/6851a94075b82375381a7236e081292b67f6bf9a[WEB]
- https://github.com/apache/camel/commit/e9c4541a91ce75ce4817d499e704299c3933edaa[WEB]
- https://camel.apache.org/security/CVE-2026-49042.html[WEB]
- https://github.com/apache/camel[PACKAGE]
- https://github.com/apache/camel/releases/tag/camel-4.18.3[WEB]
- https://github.com/apache/camel/releases/tag/camel-4.21.0[WEB]
- https://issues.apache.org/jira/browse/CAMEL-23621[WEB]
- http://www.openwall.com/lists/oss-security/2026/07/06/17[WEB]