CVE-2026-56140
Apache Software Foundation Apache Camel AWS2 SNS, camel
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originally configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel.* headers from being written out) and did not configure an inbound filter rule. For the related camel-aws2-sqs component this inbound gap was exploitable, because the Sqs2Consumer maps inbound SQS message attributes into the...
- CVSS
- 9.8
- EPSS
- 0.43% 34.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06