cbcvebase.
CVE-2025-30177
published 2025-04-01

CVE-2025-30177: Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before…

PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.01%
59.2th percentile
Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachecamel
apachecamel>= 3.0.0 < 4.14.64.14.6
apachecamel>= 3.18.0 < 4.14.64.14.6
apachecamel>= 4.10.0 < 4.10.34.10.3
apachecamel>= 4.15.0 < 4.18.14.18.1
apachecamel>= 4.15.0 < 4.18.24.18.2
apachecamel>= 4.8.0 < 4.8.64.8.6
apache_software_foundationapache_camel>= 4.10.0 < 4.10.34.10.3
apache_software_foundationapache_camel>= 4.8.0 < 4.8.64.8.6

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
ghsa5.6MEDIUM
vendor_apache6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.