GHSA-jg2m-9x48-3gvj
CRITICALCVE-2026-40453The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilte
- Affected
- >= 3.0.0, < 4.14.6
- Fixed in
- 4.14.6
- Weakness
- CWE-178
- Published
- 2026-04-27
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference