Description
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3CVEListApache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component↗2026-01-14 ▶ OSVApache Camel camel-neo4j component is vulnerable to cypher injection↗2026-01-14 ▶ GHSAApache Camel camel-neo4j component is vulnerable to cypher injection↗2026-01-14 ▶ 📋Vendor Advisories
2Red Hatcamel-neo4j: Apache Camel camel-neo4j: Unauthorized data modification via Cypher Injection↗2026-01-14 ▶ ApacheApache camel: CVE-2025-66169↗ ▶ 🕵️Threat Intelligence
1WizCVE-2025-66169 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶