CVE-2026-49086P3MEDIUMCVSS 6.5≥ 4.12.0, < 4.14.8·≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49086 [MEDIUM] CWE-20 CVE-2026-49086: Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component.
The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name and its topic - into the CamelDaprPubSubName and CamelDaprTopic Exchange headers. These two
nvd