Improper Input Validation Affecting org.apache.camel:camel-aws2-sqs package, versions [,4.14.8)[4.15.0,4.18.3)[4.19.0,4.21.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.64% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-17892595
  • published8 Jul 2026
  • disclosed6 Jul 2026
  • creditYu Bao

Introduced: 6 Jul 2026

CVE-2026-46456  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-aws2-sqs to version 4.14.8, 4.18.3, 4.21.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation through Sqs2HeaderFilterStrategy. An attacker can inject Camel control headers into an SQS message by sending message attributes such as CamelHttpUri, CamelFileName, or CamelSqlQuery to a consumed queue. Those attributes are copied into the Camel Exchange without an inbound header filter, so downstream routes can be steered into using attacker-supplied header values. This can redirect HTTP producers, alter file names, or override query parameters, breaking route behavior and exposing or manipulating data processed by the application.

CVSS Base Scores

version 4.0
version 3.1