CVE-2025-66169
published 2026-01-14CVE-2025-66169: Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.61%
45.7th percentile
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | >= 4.10.0 < 4.10.8 | 4.10.8 |
| apache | camel | >= 4.10.0 < 4.14.8 | 4.14.8 |
| apache | camel | >= 4.14.0 < 4.14.3 | 4.14.3 |
| apache | camel | >= 4.15.0 < 4.17.0 | 4.17.0 |
| apache | camel | >= 4.15.0 < 4.18.3 | 4.18.3 |
| apache | camel | >= 4.19.0 < 4.21.0 | 4.21.0 |
| apache_software_foundation | apache_camel | >= 4.10.0 < 4.14.8 | 4.14.8 |
| apache_software_foundation | apache_camel | >= 4.15.0 < 4.18.3 | 4.18.3 |
| apache_software_foundation | apache_camel | >= 4.19.0 < 4.21.0 | 4.21.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_apache5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
camel-neo4j: Apache Camel camel-neo4j: Unauthorized data modification via Cypher Injection
vendor_redhat·2026-01-14·CVSS 5.3
CVE-2025-66169 [MEDIUM] camel-neo4j: Apache Camel camel-neo4j: Unauthorized data modification via Cypher Injection
camel-neo4j: Apache Camel camel-neo4j: Unauthorized data modification via Cypher Injection
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
A flaw was found in the Apache Camel camel-neo4j component. A remote attacker can exploit this Cypher Injection vulnerability to perform unauthorized data modification or execute arbitrary database queries. This could lead to a compromise of data integrity within the Neo4j database.
Statement: This vulnerability is rated Moderate for Red Hat as it affects the `camel-neo4j` component in Red Hat build of Apache Camel.
Apache
Apache camel: CVE-2025-66169
vendor_apache·CVSS 5.3
CVE-2025-66169 [MEDIUM] Apache camel: CVE-2025-66169
Apache camel: CVE-2025-66169
Apache Camel 4.10.x before 4.10.8, Apache Camel 4.14.x before 4.14.3, Apache Camel 4.15.0 and 4.16.0. 4.10.8, 4.14.3 and 4.17.0 MEDIUM Cypher injection vulnerability in Camel-Neo4j component 2025
Severity: medium
GHSA
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.
ghsa_unreviewed·2026-07-06·CVSS 5.3
CVE-2026-46591 [MEDIUM] CWE-943 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.
The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters ($paramN), but the property names (the JSON keys of that map) were still concatenated into the query string verbatim in Neo4jProducer.retrieveNodes() and deleteNode(). A property name containing Cypher syntax therefore alters the structure of the executed query. Where a route maps untrusted input into the CamelNeo4jMatchProperties map - for example by passing a request body as the match map, or from a consumer that does not filter inboun
OSV
Apache Camel camel-neo4j component is vulnerable to cypher injection
osv·2026-01-14
CVE-2025-66169 [MEDIUM] Apache Camel camel-neo4j component is vulnerable to cypher injection
Apache Camel camel-neo4j component is vulnerable to cypher injection
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
GHSA
Apache Camel camel-neo4j component is vulnerable to cypher injection
ghsa·2026-01-14
CVE-2025-66169 [MEDIUM] CWE-74 Apache Camel camel-neo4j component is vulnerable to cypher injection
Apache Camel camel-neo4j component is vulnerable to cypher injection
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
No detection rules found.
No public exploits indexed.
2026-01-14
Published