Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-46454

CVE-2026-46454: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityCritical9.8

    Critical [CVE-2026-46454] Improper Input Validation vulnerability in Apache Camel Cometd Component

    CVE-2026-46454Source published Source updated

    Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD client directly onto the Camel message (message.setHeaders), so any header name - including Camel-internal control headers such as CamelHttpUri, CamelFileName or CamelJmsDestinationName - is accepted unmodified. Because a CometdComponent installs no Bayeux SecurityPolicy by default, any client that can complete the Bayeux handshake against the CometD endpoint can publish such a message without authentication. An attacker can therefore inject arbitrary Camel control headers that…

    Affected products in this advisory
    • Apache Camel Cometd
    Source-reported affected versions
    • 4.0.0 through 4.14.8
    • 4.15.0 through 4.18.3
    • 4.19.0 through 4.21.0.
    Source-reported fixed versions
    • 4.21.0
    • 4.14.8
    • 4.18.3
    Mitigation guidance
    • Users are recommended to upgrade to version 4.21.0, which fixes the issue.
    • If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8.
    • If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3.
    • For deployments that cannot upgrade immediately, strip the Camel control headers from inbound CometD messages before they reach any downstream producer (for example removeHeaders('Camel*') and removeHeaders('camel*') at the start of the route), and install an explicit Bayeux SecurityPolicy on the CometdComponent so that only authenticated clients can publish.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery