CVE-2026-46584P4LOWCVSS 3.7≥ 4.0.0, < 4.14.8·≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46584 [LOW] CWE-20 CVE-2026-46584: Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component.
The camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a per-message JavaMail sender with those values
nvd