CVE-2026-71300
Apache Camel25/100
exploitation likelihood
CVSS9.8
EPSS0.4%
KEVNone
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.
This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.
The camel-atmosphere-websocket producer selects which connected WebSocket peers a message is delivered to through Exchange headers, and the string values of those headers sat outside the Camel namespace: websocket.connectionKey and websocket.connectionKey.list, along with websocket.sendToAll,
EPSS 0.004 (probability of exploitation) · CVSS base 9.8 · 1 public PoC/exploit reference(s) available
Public PoC / Exploit1
Defensive review only — these references demonstrate exploitability.
References1