CVE-2025-30177 Details
Description
Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.
A bypass/injection vulnerability has been identified in the Apache Camel Camel-Undertow component, specifically in versions 4.10.0 prior to 4.10.3 and 4.8.0 prior to 4.8.6. This vulnerability arises from the component's custom header filter strategy, which only filters outgoing headers and not incoming ones. As a result, an attacker can inject Camel-specific headers that may alter the behavior of certain components, such as camel-bean or camel-exec. The vulnerability is exploitable when Camel applications are directly connected to the internet via HTTP, allowing the injection of malicious HTTP headers or request parameters that are translated into headers.
Users are advised to upgrade to Apache Camel version 4.10.3 for 4.10.x LTS or 4.8.6 for 4.8.x LTS. For those using Apache Camel 3.x releases, version 3.22.4 is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://camel.apache.org/security/CVE-2025-27636.html | [email protected] | Not Applicable |
| https://camel.apache.org/security/CVE-2025-29891.html | [email protected] | Not Applicable |
| https://lists.apache.org/thread/dj79zdgw01j337lr9gvyy4sv8xfyw8py | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-164 | Improper Neutralization of Internal Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache camel | >= 4.8.0, < 4.8.6 >= 4.10.0, < 4.10.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | Initial Analysis | [email protected] |
| Apr 1, 2025 | CVE Modified | CISA-ADP |
| Apr 1, 2025 | New CVE Received | [email protected] |