Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/oscerd/cve-2026-48203
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHuboscerd/cve-2026-48203

CVE-2026-48203

Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)

View Repository
1 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-48203 — camel-solr SolrParam. / SolrField. Header Injection

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

RuntimeDirectoryStack
Camel Spring Bootcamel-spring-boot/Spring Boot 3.2.0 + camel-spring-boot 4.18.2
Camel Quarkuscamel-quarkus/Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0)

Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect: the camel-solr producer copies any inbound header beginning with SolrField. into the indexed document and any header beginning with SolrParam. into the Solr request parameters. Those prefixes are not in the Camel* namespace, so the HTTP boundary filter does not strip them — a client of a fixed "save a note" / "search" endpoint injects arbitrary document fields (CWE-74) and Solr request parameters, including shards for server-side request forgery (CWE-918).

Both variants use a netty-http consumer (not a servlet container): the SolrField. / SolrParam. prefix match is case-sensitive, and netty-http preserves header-name case where a servlet container would lower-case it.

Each subdirectory is a self-contained project (plus a Solr container started by its docker-compose.yml) with its own Dockerfile and README. In short, for either:

root@kitploit:~
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

The Solr container runs with -Dsolr.disable.allowUrls=true so the shards SSRF reaches the internal listener; on a Solr with allowUrls configured, Solr's own defence blocks the shards SSRF, but the SolrField.* document-field injection is unaffected.

Vulnerability Summary

PropertyValue
Componentcamel-solr
Affected Classorg.apache.camel.component.solr.SolrProducer / SolrRequestConverter (prefixes SolrParam. / SolrField.)
CWECWE-20 → CWE-74 (field injection) and CWE-918 (SSRF)
ImpactInject arbitrary Solr request parameters (shards/stream.url → SSRF, qt → admin handlers) and arbitrary indexed-document fields
Affected VersionsFrom 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0
Fixed Versions4.14.8, 4.18.3, 4.21.0
JIRACAMEL-23597 (PR apache/camel#23410)
CreditYu Bao (PayPal)

Advisory: https://camel.apache.org/security/CVE-2026-48203.html

Disclaimer

These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.

Download Tool