目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-55993— Apache Camel 输入验证错误漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache Camel Atmosphere Websocket
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache camel是美国Apache基金会开源的一个企业集成模式框架。 Apache Camel存在安全漏洞,该漏洞源于Atmosphere Websocket组件中未应用HeaderFilterStrategy,导致WebSocket查询参数被映射到Camel Exchange头部映射,使客户端能够设置Camel内部控制头部(包括CamelHttpUri),从而在路由中重定向HTTP请求至攻击者指定目标,导致服务端请求伪造;同时HTTP生产者解析受控URI中的属性占位符,泄露环境变量、应用程序属性

AI 预测 9.8 利用难度: 极易 EPSS 0.86% · P57

影响版本矩阵 3

厂商产品 版本范围状态
Apache Software Foundation Apache Camel Atmosphere Websocket 4.0.0< 4.14.8 affected
4.15.0< 4.18.3 affected
4.19.0< 4.21.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-55993 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour
来源: CVE Program / CVE List V5
Vulnerability Description
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket consumer mapped inbound WebSocket query parameters into the Camel Exchange header map without applying any HeaderFilterStrategy (WebsocketConsumer.sendEventNotification() iterates the query-string map collected in WebsocketConsumer.service() and copies each entry into the Exchange). Because nothing blocked the Camel header namespace, a client connecting to the WebSocket endpoint could set Camel-internal control headers - including CamelHttpUri (Exchange.HTTP_URI) - simply by supplying them as query parameters. In a route where the WebSocket consumer feeds a downstream HTTP producer, the injected CamelHttpUri redirects the server-side HTTP request to an attacker-chosen destination (server-side request forgery - for example to an internal service or a cloud metadata endpoint). In addition, the HTTP producer resolves Camel property placeholders on the resulting (attacker-controlled) URI, so placeholders embedded in the injected value - such as an environment-variable reference, an application property, or a vault reference - are resolved to their real values and sent to the attacker, disclosing environment variables, application properties and vault secrets. When the WebSocket endpoint is exposed without authentication, this is reachable by an unauthenticated remote attacker. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. The fix makes the consumer apply the HeaderFilterStrategy it already inherits from the HTTP/servlet stack, filtering the Camel header namespace case-insensitively on inbound mapping, so externally-supplied Camel* / camel* headers are no longer copied into the Exchange. For deployments that cannot upgrade immediately, strip the Camel control headers from the inbound message before they reach any downstream producer (for example removeHeaders('Camel*') and removeHeaders('camel*') at the start of the route), require authentication on the WebSocket endpoint, and avoid bridging an untrusted consumer directly into an HTTP producer whose target URI can be driven from message headers.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
Apache Camel 输入验证错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Apache camel是美国Apache基金会开源的一个企业集成模式框架。 Apache Camel存在安全漏洞,该漏洞源于Atmosphere Websocket组件中未应用HeaderFilterStrategy,导致WebSocket查询参数被映射到Camel Exchange头部映射,使客户端能够设置Camel内部控制头部(包括CamelHttpUri),从而在路由中重定向HTTP请求至攻击者指定目标,导致服务端请求伪造;同时HTTP生产者解析受控URI中的属性占位符,泄露环境变量、应用程序属性
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache Camel Atmosphere Websocket 4.0.0 ~ 4.14.8 -

二、漏洞 CVE-2026-55993 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-55993 的情报信息

登录查看更多情报信息。

CVE-2026-55993 厂商安全公告 (1)

同批安全公告 · Apache Software Foundation · 2026-07-06 · 共 39 条

CVE-2026-46457 Apache Camel 输入验证错误漏洞
CVE-2026-48205 Apache Camel DNS 输入验证错误漏洞
CVE-2026-48204 Apache Camel 输入验证错误漏洞
CVE-2026-48203 Apache Camel 输入验证错误漏洞
CVE-2026-46726 Apache Camel Vertx Websocket 输入验证错误漏洞
CVE-2026-46592 Apache Camel 输入验证错误漏洞
CVE-2026-46591 Apache Camel 输入验证错误漏洞
CVE-2026-46590 Apache Camel 反序列化注入漏洞
CVE-2026-46585 Apache Camel 输入验证错误漏洞
CVE-2026-46584 Apache Camel 输入验证错误漏洞
CVE-2026-48206 Apache Camel 输入验证错误漏洞
CVE-2026-46456 Apache Camel 输入验证错误漏洞
CVE-2026-46455 Apache Camel 会话机制问题漏洞
CVE-2026-46454 Apache Camel 输入验证错误漏洞
CVE-2026-46453 Apache Camel 输入验证错误漏洞
CVE-2026-43865 Apache Camel 反序列化注入漏洞
CVE-2026-42527 Apache Camel 反序列化注入漏洞
CVE-2026-40859 Apache Camel 反序列化注入漏洞
CVE-2026-40047 Apache Camel 命令注入漏洞
CVE-2026-56140 Apache Camel 输入验证错误漏洞

显示前 20 条,共 39 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-55993

暂无评论


发表评论