Apache / Camel
86 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-80354 | Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace | HIGH | 8.1 | Sep 10, 2026 |
| CVE-2026-80351 | Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod | CRITICAL | 9.8 | Sep 10, 2026 |
| CVE-2026-80352 | Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects | CRITICAL | 9.8 | Sep 10, 2026 |
| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering nev… | CRITICAL | 9.8 | Aug 24, 2026 |
| CVE-2026-71300 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection | CRITICAL | 9.8 | Aug 24, 2026 |
| CVE-2026-63621 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filte… | HIGH | 7.3 | Aug 24, 2026 |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never val… | HIGH | 8.2 | Aug 24, 2026 |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result | HIGH | 7.5 | Aug 24, 2026 |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to t… | CRITICAL | 9.1 | Aug 24, 2026 |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to t… | MEDIUM | 5.5 | Aug 24, 2026 |
| CVE-2026-59230 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with hea… | MEDIUM | 6.5 | Aug 24, 2026 |
| CVE-2026-46588 | Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-46587 | Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-49042 | Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters | HIGH | 7.3 | Jul 6, 2026 |
| CVE-2026-43866 | Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder | HIGH | 8.1 | Jul 6, 2026 |
| CVE-2026-43867 | Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFil… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-56140 | Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-56139 | Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body… | MEDIUM | 5.3 | Jul 6, 2026 |
| CVE-2026-55994 | Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection… | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-55993 | Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, a… | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-53913 | Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the… | CRITICAL | 9.8 | Jul 6, 2026 |
| CVE-2026-49365 | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP resp… | MEDIUM | 5.3 | Jul 6, 2026 |
| CVE-2026-49099 | Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour | MEDIUM | 5.3 | Jul 6, 2026 |
| CVE-2026-49098 | Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP h… | MEDIUM | 6.5 | Jul 6, 2026 |
| CVE-2026-49097 | Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing… | MEDIUM | 6.5 | Jul 6, 2026 |
Showing 1 to 25 of 86 CVEs