CRITICALMaven →
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Affected packages
- org.apache.camel:camel-undertow— 4.11.0 → 4.14.9
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-78329
- https://github.com/apache/camel/pull/25367
- https://github.com/apache/camel/pull/25379
- https://github.com/apache/camel/pull/25381
- https://github.com/apache/camel/pull/25414
- https://github.com/apache/camel/commit/0484842201ed53fb52f3223f9b698868644f5b6f
- https://github.com/apache/camel/commit/1574902d79cc5d36a2e618f7470bf0cba005d5e5
- https://github.com/apache/camel/commit/859e93b4b37fe41918c50812cb1fedb20ca6b8e1
- https://camel.apache.org/security/CVE-2026-78329.html
- https://github.com/apache/camel
- https://github.com/apache/camel/releases/tag/camel-4.14.9
- https://github.com/apache/camel/releases/tag/camel-4.18.4
- https://github.com/apache/camel/releases/tag/camel-4.22.0
- https://issues.apache.org/jira/browse/CAMEL-24360
Structured record: https://osv.dev/vulnerability/GHSA-v7h8-xhh6-gfj4
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta