Sploitus

CVE-2025-30177

No indexed exploits for CVE-2025-30177 yet

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.

Affected products
Apache Camel
Apache Camel
< 4.8.6, 4.10.3
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
1.2% (64th percentile)
Weakness
CWE-164
NVD status
Analyzed
Published
2025-04-01
CVE-2025-30177 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-30177 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-30177 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.