Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-46726 — Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0) | Kitploit
उपकरण/GitHubGitHub/oscerd/cve-2026-46726
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAPI Security
GitHuboscerd/cve-2026-46726

CVE-2026-46726

Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)

रिपॉजिटरी देखें
27 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-46726 — camel-vertx-websocket Header Injection (SSRF + Secret Disclosure)

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

RuntimeDirectoryStackWebSocket feed
Camel Spring Bootcamel-spring-boot/Spring Boot 3.2.0 + camel-spring-boot 4.18.2separate port :8090
Camel Quarkuscamel-quarkus/Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0)managed Quarkus HTTP server :8080

Both are affected versions (fixed in 4.14.8 / 4.18.3 / 4.21.0), and both demonstrate the identical defect: VertxWebsocketConsumer#populateExchangeHeaders copies the WebSocket connection's query parameters onto the Exchange with no HeaderFilterStrategy. A client supplies CamelHttpUri as a query parameter and steers the downstream camel-http producer wherever it likes (SSRF, CWE-918). Because the producer also resolves Camel property placeholders on that attacker-controlled URI, an injected {{app.secret}} is expanded to its real value and sent to the attacker's collector (information exposure, CWE-200).

The two variants differ only in where the feed is served: the camel-quarkus-vertx-websocket extension always binds the consumer to the managed Quarkus HTTP server and rejects any other host/port, so the Quarkus variant serves /feed on :8080 alongside its REST endpoints. The defect is unaffected.

Each subdirectory is a self-contained project with its own Dockerfile, docker-compose.yml, and README. In short, for either:

root@kitploit:~
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

Vulnerability Summary

Advisory: https://camel.apache.org/security/CVE-2026-46726.html

Disclaimer

These reproducers are provided for security research and authorized testing only, for a publicly disclosed and fixed vulnerability. Do not use them against systems without explicit permission.

टूल डाउनलोड करें
PropertyValue
Componentcamel-vertx-websocket
Affected Classorg.apache.camel.component.vertx.websocket.VertxWebsocketConsumer#populateExchangeHeaders (no HeaderFilterStrategy on inbound query/path params)
CWECWE-20 → CWE-918 (SSRF) and CWE-200 (Information Exposure)
ImpactInject CamelHttpUri via a WebSocket query param → SSRF from a downstream HTTP producer + disclosure of env/property/vault secrets via placeholder resolution
Affected VersionsFrom 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0
Fixed Versions4.14.8, 4.18.3, 4.21.0
JIRACAMEL-23532 (PR apache/camel#23285)
CreditKamalpreet Singh