<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:28:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06059</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06059</link>
      <description>bdu:2026-06059</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06059</guid>
    </item>
    <item>
      <title>EUVD-2026-337337</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337337</link>
      <description>EUVD-2026-337337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337337</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33453</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33453</link>
      <description>&lt;p&gt;Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.&lt;/p&gt;
&lt;p&gt;Apache Camel&amp;#39;s camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec)&lt;/p&gt;
&lt;p&gt;The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.    
Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all.&lt;/p&gt;
&lt;p&gt;As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer&amp;#39;s behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.&lt;/p&gt;
&lt;p&gt;Apache Camel&amp;#39;s camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec)&lt;/p&gt;
&lt;p&gt;The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.    
Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all.&lt;/p&gt;
&lt;p&gt;As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer&amp;#39;s behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33453</guid>
    </item>
    <item>
      <title>GHSA-695c-x5gc-94gj — Apache camel-coap allows header injection that can lead to remote code execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-695c-x5gc-94gj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.camel:camel-coap&lt;/p&gt;
&lt;p&gt;Apache Camel&amp;#39;s camel-coap component is vulnerable to header injection because it maps CoAP request URI query parameters directly into Camel message headers without applying a HeaderFilterStrategy. An unauthenticated attacker can send a crafted CoAP request to inject arbitrary Camel internal headers into the exchange.&lt;/p&gt;
&lt;p&gt;When a vulnerable route forwards that exchange to a header-sensitive downstream producer, the attacker may be able to control producer behavior. For example, in routes using camel-exec, injected headers can override the configured executable and arguments, which can result in arbitrary command execution with the privileges of the Camel process. Command output may be returned to the attacker in the CoAP response.&lt;/p&gt;
&lt;p&gt;This issue affects org.apache.camel:camel-coap from 4.14.0 through 4.14.5 and from 4.18.0 before 4.18.1. It is fixed in 4.14.6, 4.18.1, and 4.19.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.camel:camel-coap&lt;/p&gt;
&lt;p&gt;Apache Camel&amp;#39;s camel-coap component is vulnerable to header injection because it maps CoAP request URI query parameters directly into Camel message headers without applying a HeaderFilterStrategy. An unauthenticated attacker can send a crafted CoAP request to inject arbitrary Camel internal headers into the exchange.&lt;/p&gt;
&lt;p&gt;When a vulnerable route forwards that exchange to a header-sensitive downstream producer, the attacker may be able to control producer behavior. For example, in routes using camel-exec, injected headers can override the configured executable and arguments, which can result in arbitrary command execution with the privileges of the Camel process. Command output may be returned to the attacker in the CoAP response.&lt;/p&gt;
&lt;p&gt;This issue affects org.apache.camel:camel-coap from 4.14.0 through 4.14.5 and from 4.18.0 before 4.18.1. It is fixed in 4.14.6, 4.18.1, and 4.19.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-695c-x5gc-94gj</guid>
    </item>
    <item>
      <title>RHSA-2026:17668 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.18.1 for Spring Boot release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:17668</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid org.eclipse.jetty.ee10/jetty-ee10: early return from the JASPIAuthenticator class without clearing ThreadLocal variables camel-infinispan: camel-infinispan: Remote Code Execution via Unsafe Deserialization Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication Apache Camel: camel-coap: Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection Apache Camel: Camel-Mail: Camel-Mail: Altered application behavior via header injection io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid org.eclipse.jetty.ee10/jetty-ee10: early return from the JASPIAuthenticator class without clearing ThreadLocal variables camel-infinispan: camel-infinispan: Remote Code Execution via Unsafe Deserialization Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication Apache Camel: camel-coap: Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection Apache Camel: Camel-Mail: Camel-Mail: Altered application behavior via header injection io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:17668</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1286 — Apache Camel (Camel-Coap): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1286</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Camel ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Camel ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1286</guid>
    </item>
  </channel>
</rss>
