Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-46457

CVE-2026-46457: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-46457] Improper Input Validation vulnerability in Apache Camel NATS component

    CVE-2026-46457Source published Source updated

    Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured (NatsConfiguration). With no inFilter, inFilterPattern or inFilterStartsWith set, DefaultHeaderFilterStrategy.applyFilterToExternalHeaders returns not filtered for every header name, so NatsConsumer copies every NATS message header - including Camel-internal control headers such as CamelHttpUri, CamelFileName or CamelSqlQuery - unmodified onto the Camel message. A client able to publish to the consumed NATS subject can therefore inject arbitrary Camel control headers that influence the behaviour of downstream producers in…

    Affected products in this advisory
    • Apache Camel NATS
    Source-reported affected versions
    • 4.0.0 through 4.14.8
    • 4.15.0 through 4.18.3
    • 4.19.0 through 4.21.0.
    Source-reported fixed versions
    • 4.21.0
    • 4.14.8
    • 4.18.3
    Mitigation guidance
    • Users are recommended to upgrade to version 4.21.0, which fixes the issue.
    • If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8.
    • If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3.
    • For deployments that cannot upgrade immediately, strip the Camel control headers from inbound NATS messages before they reach any downstream producer (for example removeHeaders('Camel*') and removeHeaders('camel*') at the start of the route), and enable authentication on the NATS server so that only trusted clients can publish to the consumed subject.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery