CVE-2026-48204
CVE-2026-48204: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityCritical9.8
Critical [CVE-2026-48204] Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component
CVE-2026-48204Source published Source updated
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs.operation, gridfs.objectid, gridfs.metadata, gridfs.chunksize and gridfs.fileid. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a…
- Affected products in this advisory
- Apache Camel
- Source-reported affected versions
- 4.0.0 through 4.14.8
- 4.15.0 through 4.18.3
- 4.19.0 through 4.21.0.
- Source-reported fixed versions
- 4.21.0
- 4.14.8
- 4.18.3
- Mitigation guidance
- In a route that bridges an HTTP consumer (for example platform-http) into a mongodb-gridfs: producer with no explicit operation, any HTTP client could therefore set the gridfs.operation header to override the route's intended operation - switching, for example, a file upload to remove (deleting a file identified by the attacker-supplied gridfs.objectid), listAll (enumerating every file in the bucket) or findOne (reading a file) - and supply a gridfs.metadata value that is parsed as a MongoDB document, enabling NoSQL operator injection.
- Users are recommended to upgrade to version 4.21.0, which fixes the issue.
- If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8.
- If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3.
1 more entries in the full advisory.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.