SecBoard
Zurück zur CVE-Übersicht

CVE-2026-49098

MEDIUM(5.3)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Risk Signal Score13/100 — NIEDRIG
  • CVSS 5.3 — Mittel

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.6%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

5.3

Technische Schwere

Beschreibung

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer can override its configured target topic at runtime from the kafka.OVERRIDE_TOPIC Exchange header: KafkaProducer.evaluateTopic() returns the header value in preference to the topic configured on the endpoint. The control-header constants in KafkaConstants (for example OVERRIDE_TOPIC = kafka.OVERRIDE_TOPIC, OVERRIDE_TIMESTAMP = kafka.OVERRIDE_TIMESTAMP, PARTITION_KEY = kafka.PARTITION_KEY) used plain, non-Camel-prefixed values. camel-kafka's own KafkaHeaderFilterStrategy does filter the kafka.* namespace, but only on the Kafka-to-Exchange serialization boundary (reading Kafka record headers into the Exchange, and writing Exchange headers into a Kafka record); it does not apply to headers that arrive from an upstream consumer in a multi-component route. The upstream HTTP consumer uses HttpHeaderFilterStrategy, which blocks only the Camel / camel namespace, so a kafka.* header passes through unfiltered. As a result, in a route that bridges an HTTP consumer (for example platform-http) into a kafka: producer, any HTTP client could set the kafka.OVERRIDE_TOPIC header and cause the message to be published to an arbitrary Kafka topic instead of the configured one - redirecting it to a sensitive internal topic, or injecting attacker-crafted messages into a topic consumed by a critical downstream service. The related kafka.OVERRIDE_TIMESTAMP and kafka.PARTITION_KEY headers could likewise be injected to backdate messages or target specific partitions. No credentials are required when the bridging consumer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, routes that set or read Kafka headers via the raw header names must use the CamelKafka* names (for example CamelKafkaOverrideTopic and CamelKafkaTopic) instead of the old kafka.* values. For deployments that cannot upgrade immediately, strip the kafka.* headers from any untrusted ingress before the kafka: producer (for example removeHeaders('kafka.*') at the start of the route), and set the target topic from a trusted source.

Erkennung & Indikatoren

Ausnutzung

In den geprüften Quellen nicht genannt

Behobene Versionen

  • 4.14.8
  • 4.18.3
  • 4.21.0

Threat-Hunting-Queries

Diese Detektionslogik zielt auf ungewöhnliche HTTP-Header ab, die auf die Schwachstelle 'kafka.OVERRIDE_TOPIC' in Apache Camel Kafka hindeuten könnten. Da die Schwachstelle durch das Setzen spezifischer 'kafka.*'-Header in HTTP-Anfragen ausgenutzt wird, die dann an einen Kafka-Produzenten weitergeleitet werden, suchen die Abfragen nach HTTP-Anfragen, die diese Header enthalten. Eine genaue Erkennu

Sentinel/Defender KQL

let suspicious_kafka_headers = dynamic(['kafka.OVERRIDE_TOPIC', 'kafka.OVERRIDE_TIMESTAMP', 'kafka.PARTITION_KEY']);
HttpRequests
| where Url contains "kafka:" // Annahme: HTTP-Anfragen, die an Kafka-Produzenten weitergeleitet werden
| where RequestHeaders has_any (suspicious_kafka_headers)
| project TimeGenerated, ClientIP, RequestMethod, RequestUri, RequestHeaders, UserAgent

Splunk SPL

index=your_web_server_logs (http_request_headers="*kafka.OVERRIDE_TOPIC*" OR http_request_headers="*kafka.OVERRIDE_TIMESTAMP*" OR http_request_headers="*kafka.PARTITION_KEY*")
| table _time, client_ip, method, uri, http_request_headers, user_agent

Sigma

title: Apache Camel Kafka Header Injection Attempt
id: 9a7b8c1d-2e3f-4a5b-6c7d-8e9f0a1b2c3d
status: experimental
description: Detects HTTP requests attempting to inject Kafka control headers into Apache Camel Kafka components.
references:
  - https://camel.apache.org/security/CVE-2026-49098.html
author: SecBoard
date: 2026/07/05
logsource:
  category: webserver
  product: apache
  service: access
detection:
  selection:
    http_request_headers|contains:
      - 'kafka.OVERRIDE_TOPIC'
      - 'kafka.OVERRIDE_TIMESTAMP'
      - 'kafka.PARTITION_KEY'
  condition: selection
level: medium

Elastic ES|QL

FROM logs-webserver-apache-access-*
| WHERE http.request.headers.kafka_override_topic IS NOT NULL OR http.request.headers.kafka_override_timestamp IS NOT NULL OR http.request.headers.kafka_partition_key IS NOT NULL
| SELECT @timestamp, client.ip, http.request.method, url.original, http.request.headers, user_agent.original

SecBoard-generated · behavioral · requires customizationVon SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Indikatoren

Datei-Hashes (3)

  • f8914a219ad473811c01562b5b85e83ba583b583
  • d4c6fd85358b65d99dfe26722278eaf35fd0029c
  • 93cd4c4e1d1619d71aa9b56c3850d4d6ccd74375

Übernommen wurden nur Indikatoren, die wörtlich in einer Hersteller- oder Research-Quelle standen.

GitHub Advisories

GHSA-mm84-qvjh-hcj7MEDIUM

Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter

maven/org.apache.camel:camel-kafka4.14.8
GitHub Advisory

Referenzen