
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a read to a destructive one (fixed in 4.14.8/4.18.3/4.21.0)
operationName Header Injection (SOAP Operation Redirection)Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:
| Runtime | Directory | Stack | Backend SOAP service |
|---|---|---|---|
| Camel Spring Boot | camel-spring-boot/ | Spring Boot 3.2.0 + camel-spring-boot 4.18.2 | CXF ServerFactoryBean on its own port :9000 |
| Camel Quarkus | camel-quarkus/ | Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0) | quarkus-cxf on the managed server, /soapservice/account |
Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect:
CxfProducer#getBindingOperationInfo first looks for an operationName message header and only falls back to
the endpoint's defaultOperationName when it is absent. That header constant's value is the plain string
operationName — not CamelCxfOperationName — so the HTTP boundary filter (which strips only Camel*) lets an
inbound HTTP header of that name straight through. An untrusted client adds operationName: deleteAccount and
the route's pinned, read-only getBalance becomes a destructive call (CWE-441, confused deputy).
The two variants differ only in how the backend SOAP service is stood up: the Quarkus variant publishes it with quarkus-cxf on the managed Quarkus HTTP server (so the contract carries JAX-WS
@WebServiceannotations), while the Spring Boot variant creates it programmatically with a CXFServerFactoryBeanon a separate port. The defect is unaffected.
Each subdirectory is a self-contained project with its own Dockerfile, docker-compose.yml, and README. In
short, for either:
cd camel-spring-boot # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
Advisory: https://camel.apache.org/security/CVE-2026-46592.html
These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.
| Property | Value |
|---|
| Component | camel-cxf (camel-cxf-soap; the constant lives in camel-cxf-common, so camel-cxfrs is affected too) |
| Affected Class | org.apache.camel.component.cxf.jaxws.CxfProducer#getBindingOperationInfo reading CxfConstants.OPERATION_NAME ("operationName") |
| CWE | CWE-20 (Improper Input Validation) / CWE-441 (Unintended Proxy or Intermediary — Confused Deputy) |
| Impact | An HTTP client sets operationName → the producer invokes a different SOAP operation (e.g. a destructive one) |
| Affected Versions | From 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0 |
| Fixed Versions | 4.14.8, 4.18.3, 4.21.0 |
| JIRA | CAMEL-23526 (PR apache/camel#23326) |
| Credit | Yu Bao (PayPal) |