CVE-2025-27636Improper Handling of Case Sensitivity in Software Foundation Apache Camel

Severity
5.6MEDIUMNVD
EPSS
57.8%
top 1.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateJul 15

Description

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can al

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.2 | Impact: 3.4

Affected Packages2 packages

NVDapache/camel3.10.03.22.4+2
CVEListV5apache_software_foundation/apache_camel4.10.04.10.2+2

Patches

🔴Vulnerability Details

4
CVEList
Apache Camel: Camel Message Header Injection via Improper Filtering2025-03-09
OSV
Apache Camel: Camel Message Header Injection via Improper Filtering2025-03-09
GHSA
Apache Camel: Camel Message Header Injection via Improper Filtering2025-03-09
VulnCheck
Apache camel Improper Handling of Case Sensitivity2025

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Apache Camel Message Header Injection (CVE-2025-27636)2025-03-10

📋Vendor Advisories

3
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Maintenance (Apache Camel) — CVE-2025-276362025-07-15
Red Hat
camel-http: org.apache.camel: bypass of header filters via specially crafted response2025-03-10
Apache
Apache camel: CVE-2025-27636

🕵️Threat Intelligence

2
Unit42
Apache Under the Lens: Tomcat’s Partial PUT and Camel’s Header Hijack2025-07-03
Unit42
Apache Under the Lens: Tomcat’s Partial PUT and Camel’s Header Hijack2025-07-03
CVE-2025-27636 — Improper Handling of Case Sensitivity | cvebase