Apache / Apache Camel
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering nev… | CRITICAL | 9.8 | Aug 24, 2026 |
| CVE-2026-71300 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection | CRITICAL | 9.8 | Aug 24, 2026 |
| CVE-2026-63621 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filte… | HIGH | 7.3 | Aug 24, 2026 |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never val… | HIGH | 8.2 | Aug 24, 2026 |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result | HIGH | 7.5 | Aug 24, 2026 |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to t… | CRITICAL | 9.1 | Aug 24, 2026 |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to t… | MEDIUM | 5.5 | Aug 24, 2026 |
| CVE-2026-59230 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with hea… | MEDIUM | 6.5 | Aug 24, 2026 |
| CVE-2026-46588 | Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-46587 | Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-49042 | Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-43866 | Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder | HIGH | 8.1 | Jul 6, 2026 |
| CVE-2026-43867 | Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFil… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-49365 | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP resp… | MEDIUM | 5.3 | Jul 6, 2026 |
| CVE-2026-49098 | Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP h… | MEDIUM | 6.5 | Jul 6, 2026 |
| CVE-2026-49097 | Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing… | MEDIUM | 6.5 | Jul 6, 2026 |
| CVE-2026-48204 | Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to s… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-48203 | Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an… | CRITICAL | 9.1 | Jul 6, 2026 |
| CVE-2026-46592 | Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header fil… | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-46591 | Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allo… | HIGH | 8.2 | Jul 6, 2026 |
| CVE-2026-46590 | Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream a… | HIGH | 8.8 | Jul 6, 2026 |
| CVE-2026-46457 | Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publi… | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-46456 | Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inj… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-46455 | Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-46454 | Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inj… | CRITICAL | 9.8 | Jul 6, 2026 |
Showing 1 to 25 of 52 CVEs