


Perceptive Security
SOC/SIEM Consultancy

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operation parameter…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 21:04:26
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Network Infrastructure
CVE-2026-48205 is an Improper Input Validation and Server-Side Request Forgery (SSRF) vulnerability in the Apache Camel DNS component. The camel-dns producers read DNS operation parameters from Exchange message headers using plain string names (e.g., dns.server, dns.name) that do not start with the Camel prefix, causing HttpHeaderFilterStrategy to allow them to pass through the HTTP boundary unfiltered. In routes bridging an HTTP consumer to a DNS producer, an unauthenticated attacker can set the dns.server header to redirect DNS queries to an attacker-controlled server, enabling DNS poisoning and SSRF. Additionally, attackers can set dns.name or dns.domain headers to resolve arbitrary internal hostnames, facilitating internal network reconnaissance. The vulnerability affects Apache Camel versions 4.0.0 before 4.14.8, 4.15.0 before 4.18.3, and 4.19.0 before 4.21.0. No credentials are required to exploit this when the bridging consumer is unauthenticated. Users are recommended to upgrade to 4.21.0, 4.14.8, or 4.18.3 depending on their release stream, and to rename DNS headers to the new CamelDns* prefixed constants.
Technical details
Mitigation steps:
Affected products:
Apache Camel 4.0.0 - 4.14.7
Apache Camel 4.15.0 - 4.18.2
Apache Camel 4.19.0 - 4.20.x
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48205
https://camel.apache.org/security/CVE-2026-48205.html
http://www.openwall.com/lists/oss-security/2026/07/05/19
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
