Improperly Controlled Modification of Dynamically-Determined Object Attributes Affecting org.apache.camel:camel-irc package, versions [4.0.0,4.14.8)[4.15.0,4.18.3)[4.19.0,4.21.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.56% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-17875077
  • published7 Jul 2026
  • disclosed6 Jul 2026
  • creditUnknown

Introduced: 6 Jul 2026

NewCVE-2026-49097  (opens in a new tab)
CWE-915  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-irc to version 4.14.8, 4.18.3, 4.21.0 or higher.

Overview

Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes via the irc.sendTo header and other irc.* headers in HTTP requests. An attacker can redirect outgoing IRC messages to arbitrary channels or users by injecting specially crafted headers into an HTTP request that bridges to an IRC producer, potentially exfiltrating message content or impersonating the bot.

CVSS Base Scores

version 4.0
version 3.1