MAVEN · JULY 2026 · EARLY WARNING

Apache Camel DNS Vulnerability: SSRF Risk Due to Improper Input Validation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-HCM8-X79P-WX2WSeverity: HIGH

An early warning has been issued regarding a vulnerability in the Apache Camel DNS component that may allow Server-Side Request Forgery (SSRF) due to improper input validation. Users of affected versions are advised to upgrade.

What happened

Reportedly, a critical vulnerability has been identified in the Apache Camel DNS component, tracked under GHSA-HCM8-X79P-WX2W. This vulnerability appears to stem from improper input validation, which could lead to Server-Side Request Forgery (SSRF). An attacker exploiting this flaw may be able to perform internal network reconnaissance by resolving arbitrary internal hostnames. The affected versions include camel-dns (maven) prior to 4.14.8, 4.18.3, or 4.21.0. It is under investigation whether a compromise has occurred. As a recommended action, users are advised to upgrade to Apache Camel version 4.21.0 or, if on the 4.14.x or 4.18.x release streams, upgrade to 4.14.8 or 4.18.3 respectively. Additionally, it is recommended to use CamelDnsServer, CamelDnsName, CamelDnsDomain, CamelDnsType, CamelDnsClass, CamelDnsTerm instead of dns.* / term names in DNS operations. For more detailed information, primary sources should be consulted.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If camel-dns is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats