Apache Camel vulnerabilities
74 known vulnerabilities affecting apache/camel.
Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL25HIGH31MEDIUM16LOW2
Vulnerabilities
Page 1 of 4
CVE-2025-27636P2MEDIUMCVSS 5.6ExploitedPoC≥ 3.10.0, < 3.22.4≥ 4.8.0, < 4.8.5+1 more2025-03-09
CVE-2025-27636 [MEDIUM] CWE-178 CVE-2025-27636: Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue a
Bypass/Injection vulnerability in Apache Camel components under particular conditions.
This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3.
Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.
This vulnerability is
nvd
CVE-2025-29891P2MEDIUMCVSS 4.8ExploitedPoC≥ 3.10.0, < 3.22.4≥ 4.8.0, < 4.8.5+1 more2025-03-12
CVE-2025-29891 [MEDIUM] CVE-2025-29891: Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before
Bypass/Injection vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4.
Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.
This vulnerability is present in Camel's default incoming header filter, that all
nvd
CVE-2026-33453P1CRITICALCVSS 10.0PoC≥ 4.14.0, ≤ 4.14.5v4.18.0+1 more2026-04-27
CVE-2026-33453 [CRITICAL] CWE-915 CVE-2026-33453: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apac
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.
Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec)
The camel-coap c
nvd
CVE-2026-53913P2CRITICALCVSS 9.8≥ 4.15.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-53913 [CRITICAL] CVE-2026-53913: Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failin
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.
The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no acces
nvd
CVE-2026-47323P2CRITICALCVSS 9.8≥ 3.18.0, < 4.14.6≥ 4.15.0, < 4.18.22026-05-19
CVE-2026-47323 [CRITICAL] CVE-2026-47323: Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knat
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) only filter outbound Camel-internal headers via setOutFilterStar
nvd
CVE-2026-40453P2CRITICALCVSS 9.9≥ 3.0.0, < 4.14.6≥ 4.15.0, < 4.18.2+1 more2026-04-27
CVE-2026-40453 [CRITICAL] CVE-2026-40453: The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderF
nvd
CVE-2026-40860P2CRITICALCVSS 9.8≥ 3.0.0, < 4.14.7≥ 4.15.0, < 4.18.2+1 more2026-04-27
CVE-2026-40860 [CRITICAL] CWE-502 CVE-2026-40860: JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, des
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enab
nvd
CVE-2026-43867P2CRITICALCVSS 9.8≥ 4.18.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-43867 [CRITICAL] CVE-2026-43867: Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc compon
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that metadata back from the configured AWS Secrets Manager secret by Base64-decoding
nvd
CVE-2026-46454P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46454 [CRITICAL] CWE-20 CVE-2026-46454: Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd componen
Improper Input Validation vulnerability in Apache Camel Cometd Component.
The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD client directly onto the Camel mess
nvd
CVE-2026-25747P2HIGHCVSS 8.8≥ 3.0.0, < 4.10.9≥ 4.11.0, < 4.14.5+1 more2026-02-23
CVE-2026-25747 [HIGH] CWE-502 CVE-2026-25747: Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelD
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component.
The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files
nvd
CVE-2026-40473P2HIGHCVSS 8.8≥ 3.0.0, < 4.14.6≥ 4.15.0, < 4.18.2+1 more2026-04-27
CVE-2026-40473 [HIGH] CWE-502 CVE-2026-40473: The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via getBody(ObjectInput.class) or @Body Ob
nvd
CVE-2015-5344P2CRITICALCVSS 9.8≤ 2.15.4v2.16.02016-02-03
CVE-2015-5344 [CRITICAL] CWE-19 CVE-2015-5344: The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote atta
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
nvd
CVE-2014-0002P3HIGHCVSS 7.5≤ 2.11.3v1.0.0+26 more2014-03-21
CVE-2014-0002 [HIGH] CWE-264 CVE-2014-0002: The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2026-46456P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46456 [CRITICAL] CWE-20 CVE-2026-46456: Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs com
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrategy configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel.*
nvd
CVE-2026-40047P2CRITICALCVSS 9.1≥ 4.15.0, < 4.18.32026-07-06
CVE-2026-40047 [CRITICAL] CWE-88 CVE-2026-40047: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.
The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through th
nvd
CVE-2016-8749P2CRITICALCVSS 9.8v2.16.0v2.16.1+10 more2017-03-28
CVE-2016-8749 [CRITICAL] CWE-502 CVE-2016-8749: Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Executio
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
nvd
CVE-2026-56140P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-56140 [CRITICAL] CVE-2026-56140: Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns comp
Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originally configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and or
nvd
CVE-2026-46590P2HIGHCVSS 8.8≥ 4.18.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-46590 [HIGH] CVE-2026-46590: Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc compon
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a B
nvd
CVE-2024-23114P2CRITICALCVSS 9.8≥ 3.0.0, < 3.21.4≥ 4.0.0, < 4.0.4+2 more2024-02-20
CVE-2024-23114 [CRITICAL] CWE-502 CVE-2024-23114: Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRep
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.
nvd
CVE-2026-48204P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-48204 [CRITICAL] CWE-20 CVE-2026-48204: Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gr
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConsta
nvd
1 / 4Next →