
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
| Runtime | Directory | Stack |
|---|
| Camel Spring Boot | camel-spring-boot/ | Spring Boot 3.2.0 + camel-spring-boot 4.18.2 |
| Camel Quarkus | camel-quarkus/ | Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0) |
Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect: the
camel-solr producer copies any inbound header beginning with SolrField. into the indexed document and any header
beginning with SolrParam. into the Solr request parameters. Those prefixes are not in the Camel* namespace, so
the HTTP boundary filter does not strip them — a client of a fixed "save a note" / "search" endpoint injects
arbitrary document fields (CWE-74) and Solr request parameters, including shards for server-side request forgery
(CWE-918).
Both variants use a netty-http consumer (not a servlet container): the SolrField. / SolrParam. prefix match
is case-sensitive, and netty-http preserves header-name case where a servlet container would lower-case it.
Each subdirectory is a self-contained project (plus a Solr container started by its docker-compose.yml) with its
own Dockerfile and README. In short, for either:
cd camel-spring-boot # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
The Solr container runs with -Dsolr.disable.allowUrls=true so the shards SSRF reaches the internal listener;
on a Solr with allowUrls configured, Solr's own defence blocks the shards SSRF, but the SolrField.*
document-field injection is unaffected.
| Property | Value |
|---|---|
| Component | camel-solr |
| Affected Class | org.apache.camel.component.solr.SolrProducer / SolrRequestConverter (prefixes SolrParam. / SolrField.) |
| CWE | CWE-20 → CWE-74 (field injection) and CWE-918 (SSRF) |
| Impact | Inject arbitrary Solr request parameters (shards/stream.url → SSRF, qt → admin handlers) and arbitrary indexed-document fields |
| Affected Versions | From 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0 |
| Fixed Versions | 4.14.8, 4.18.3, 4.21.0 |
| JIRA | CAMEL-23597 (PR apache/camel#23410) |
| Credit | Yu Bao (PayPal) |
These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.