Skip to content

CAMEL-23522: camel-mail - gate JavaMail session properties from headers behind opt-in - #23362

Merged
oscerd merged 1 commit into
apache:mainfrom
oscerd:fix/CAMEL-23522
May 20, 2026
Merged

oscerd merged 1 commit into
apache:mainfrom
oscerd:fix/CAMEL-23522

Conversation

@oscerd

@oscerd oscerd commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

Companion to CAMEL-23222 / the CVE-2025-27636 header-injection family, addressing a namespace missed in that sweep.

MailProducer.getSender extracted mail.smtp.* / mail.smtps.* exchange headers and applied them as JavaMail session properties on a per-message custom sender. The namespace is Camel-internal (only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy. A route chaining an untrusted producer (e.g. platform-http query parameters, JMS/Kafka from untrusted producers) into smtp/smtps without an explicit removeHeaders between them therefore let an attacker drive transport-security settings: mail.smtp.ssl.trust, mail.smtp.ssl.checkserveridentity, mail.smtp.starttls.enable, mail.smtp.socks.host, etc.

This PR makes the per-message override opt-in.

Changes

  • MailConfiguration — new @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label="producer,advanced,security", security="insecure:ssl"). Picked up automatically by the SECURITY-OPTIONS generator and added to core/camel-util/SecurityUtils so the project-wide security-policy framework can govern it.
  • MailProducer.getSender — returns the default sender unconditionally when the flag is false. Existing extraction path preserved when the flag is true.
  • MailHeaderFilterStrategy — extends the inbound setInFilterStartsWith set with mail.smtp. / mail.smtps. (defense in depth, mirroring CAMEL-23222 for the Camel* namespace). Outbound filtering is unchanged.
  • Docs — mail-component.adoc documents the new opt-in URI and the security caveat, with a cross-link to the project security model; pre-existing java.smtp. typo in the same section corrected to mail.smtp..
  • Upgrade guide — new camel-mail entry in camel-4x-upgrade-guide-4_21.adoc documenting the default tightening and the opt-in URI.
  • Tests — MailSessionPropertiesFromHeadersTest covers both flag values plus the no-header path; MailHeaderFilterStrategyTest covers the new inbound prefix filtering, retention of Camel* filtering, ordinary mail headers passing through, and outbound being unaffected.

Backwards compatibility

This is a default-tightening breaking change, intentionally aligned with the CAMEL-23222 / CVE-2025-27636-family precedent of shipping default-secure even in patch releases. Routes that legitimately rely on per-message mail.smtp.* headers must opt back in on the endpoint:

.to("smtp://mymailserver:1234?useJavaMailSessionPropertiesFromHeaders=true");

Even with the opt-in enabled, route authors should still strip the namespace with removeHeaders("mail.smtp.*", "mail.smtps.*") between any untrusted ingress and the mail producer — see the upgrade guide for the full rationale.

Test plan

  • mvn test in components/camel-mail — 218/218 pass (4 skipped, no regressions).
  • New focused tests: MailSessionPropertiesFromHeadersTest (3 tests), MailHeaderFilterStrategyTest (4 tests).
  • Full-reactor mvn clean install -DskipTests from root — exit 0; cross-module catalog mirrors, DSL builder factories, endpoint DSL, and SecurityUtils regen all included in the commit.

Backports

fixVersions on the Jira issue are 4.21.0, 4.18.3, 4.14.8. The 4.18.x and 4.14.x backports will need light adaptation:

  • 4.18.x: same code shape as main post-PR; straightforward cherry-pick.
  • 4.14.x: pre-dates CAMEL-22900 (no mail.smtps. fallback) and CAMEL-23308 (no configureJavaMailSender on the custom sender). The flag and the getSender gate apply identically; the MailHeaderFilterStrategy change applies identically.

Backport PRs to follow once this lands on main.

Linked issue

https://issues.apache.org/jira/browse/CAMEL-23522


Claude Code on behalf of Andrea Cosentino

…rs behind opt-in

MailProducer.getSender extracted mail.smtp.* / mail.smtps. exchange headers and applied them as
JavaMail session properties on a per-message custom sender. The namespace is Camel-internal
(only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy, so a route
chaining an untrusted producer (platform-http, JMS, Kafka, ...) into smtp/smtps without an
explicit removeHeaders between them let an attacker drive transport-security settings
(mail.smtp.ssl.trust, mail.smtp.starttls.enable, mail.smtp.socks.host, ...).

This is the same conceptual pattern as the Camel* header injection family (CAMEL-23222 /
CVE-2025-27636), with a namespace that was missed in that sweep.

Changes:

* New @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label
  producer,advanced,security, security=insecure:ssl) on MailConfiguration. When false,
  MailProducer.getSender always returns the default sender.
* MailHeaderFilterStrategy now also filters mail.smtp. / mail.smtps. on the inbound path
  (defense in depth, mirroring CAMEL-23222).
* Doc note in mail-component.adoc with the security warning and the opt-in URI.
* Upgrade-guide entry in camel-4x-upgrade-guide-4_21.adoc.
* Tests for both flag values and for the header-filter strategy behaviour.

The build's SECURITY-OPTIONS generator picked up the new annotation and added the property to
the policy-enforceable map in core/camel-util SecurityUtils.

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@oscerd
oscerd requested review from Croway, davsclaus and gnodet May 20, 2026 09:12
@github-actions

Copy link
Copy Markdown
Contributor

🌟 Thank you for your contribution to the Apache Camel project! 🌟
🤖 CI automation will test this PR automatically.

🐫 Apache Camel Committers, please review the following items:

  • First-time contributors require MANUAL approval for the GitHub Actions to run
  • You can use the command /component-test (camel-)component-name1 (camel-)component-name2.. to request a test from the test bot although they are normally detected and executed by CI.
  • You can label PRs using skip-tests and test-dependents to fine-tune the checks executed by this PR.
  • Build and test logs are available in the summary page. Only Apache Camel committers have access to the summary.

⚠️ Be careful when sharing logs. Review their contents before sharing them publicly.

@github-actions

Copy link
Copy Markdown
Contributor

🧪 CI tested the following changed modules:

  • catalog/camel-catalog
  • components/camel-mail
  • core/camel-util
  • dsl/camel-componentdsl
  • dsl/camel-endpointdsl

ℹ️ Dependent modules were not tested because the total number of affected modules exceeded the threshold (50). Use the test-dependents label to force testing all dependents.

Build reactor — dependencies compiled but only changed modules were tested (5 modules)
  • Camel :: Catalog :: Camel Catalog
  • Camel :: Component DSL
  • Camel :: Endpoint DSL
  • Camel :: Mail
  • Camel :: Util

⚙️ View full build and test results

@oscerd
oscerd merged commit 1e31abc into apache:main May 20, 2026
7 checks passed
oscerd added a commit that referenced this pull request May 21, 2026
…rs behind opt-in (#23362) (#23381)

MailProducer.getSender extracted mail.smtp.* / mail.smtps. exchange headers and applied them as
JavaMail session properties on a per-message custom sender. The namespace is Camel-internal
(only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy, so a route
chaining an untrusted producer (platform-http, JMS, Kafka, ...) into smtp/smtps without an
explicit removeHeaders between them let an attacker drive transport-security settings
(mail.smtp.ssl.trust, mail.smtp.starttls.enable, mail.smtp.socks.host, ...).

This is the same conceptual pattern as the Camel* header injection family (CAMEL-23222 /
CVE-2025-27636), with a namespace that was missed in that sweep.

Changes:

* New @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label
  producer,advanced,security, security=insecure:ssl) on MailConfiguration. When false,
  MailProducer.getSender always returns the default sender.
* MailHeaderFilterStrategy now also filters mail.smtp. / mail.smtps. on the inbound path
  (defense in depth, mirroring CAMEL-23222).
* Doc note in mail-component.adoc with the security warning and the opt-in URI.
* Upgrade-guide entry in camel-4x-upgrade-guide-4_21.adoc.
* Tests for both flag values and for the header-filter strategy behaviour.

The build's SECURITY-OPTIONS generator picked up the new annotation and added the property to
the policy-enforceable map in core/camel-util SecurityUtils.

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
oscerd added a commit that referenced this pull request May 21, 2026
…ating (#23383)

Mirror the 4.18.x upgrade-guide entry for CAMEL-23522 (camel-mail - gate JavaMail session
properties from headers behind opt-in) onto main, per the project's backport upgrade-guide
policy: the camel-4x-upgrade-guide-4_XX.adoc files on main act as the canonical history
across all releases, so any entry added on a maintenance branch must also land here.

Companion to the backport PR against camel-4.18.x (#23381) and the main PR (#23362).

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
oscerd added a commit that referenced this pull request May 21, 2026
…ating (#23418)

Mirror the 4.14.x upgrade-guide entry for CAMEL-23522 (camel-mail - gate JavaMail session
properties from headers behind opt-in) onto main, per the project's backport upgrade-guide
policy: the camel-4x-upgrade-guide-4_XX.adoc files on main act as the canonical history
across all releases, so any entry added on a maintenance branch must also land here.

Companion to the backport PR against camel-4.14.x (#23416), the 4.18.x backport (#23381), the
4.18 doc-sync (#23383) and the main PR (#23362).

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
oscerd added a commit that referenced this pull request May 21, 2026
…rs behind opt-in (#23362) (#23416)

MailProducer.getSender extracted mail.smtp.* / mail.smtps. exchange headers and applied them as
JavaMail session properties on a per-message custom sender. The namespace is Camel-internal
(only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy, so a route
chaining an untrusted producer (platform-http, JMS, Kafka, ...) into smtp/smtps without an
explicit removeHeaders between them let an attacker drive transport-security settings
(mail.smtp.ssl.trust, mail.smtp.starttls.enable, mail.smtp.socks.host, ...).

This is the same conceptual pattern as the Camel* header injection family (CAMEL-23222 /
CVE-2025-27636), with a namespace that was missed in that sweep.

Changes:

* New @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label
  producer,advanced,security, security=insecure:ssl) on MailConfiguration. When false,
  MailProducer.getSender always returns the default sender.
* MailHeaderFilterStrategy now also filters mail.smtp. / mail.smtps. on the inbound path
  (defense in depth, mirroring CAMEL-23222).
* Doc note in mail-component.adoc with the security warning and the opt-in URI.
* Upgrade-guide entry in camel-4x-upgrade-guide-4_21.adoc.
* Tests for both flag values and for the header-filter strategy behaviour.

The build's SECURITY-OPTIONS generator picked up the new annotation and added the property to
the policy-enforceable map in core/camel-util SecurityUtils.

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@oscerd
oscerd deleted the fix/CAMEL-23522 branch October 2, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants