cbcvebase.

Apache Camel vulnerabilities

74 known vulnerabilities affecting apache/camel.

Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL25HIGH31MEDIUM16LOW2

Vulnerabilities

Page 3 of 4
CVE-2026-46591P3HIGHCVSS 8.2≥ 4.10.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46591 [HIGH] CVE-2026-46591: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters ($p
nvd
CVE-2026-55993P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-55993 [HIGH] CWE-20 CVE-2026-55993: Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket consumer mapped inbound WebSocket query parameters into the Camel Exchange header map without applying any HeaderFilterStrategy (Websoc
nvd
CVE-2026-46726P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46726 [HIGH] CWE-20 CVE-2026-46726: Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket component. The camel-vertx-websocket consumer mapped inbound WebSocket query and path parameters into the Camel Exchange header map without applying any HeaderFilterStrategy (VertxWe
nvd
CVE-2018-8027P3CRITICALCVSS 9.8≥ 2.20.0, ≤ 2.20.3v2.21.02018-07-31
CVE-2018-8027 [CRITICAL] CWE-611 CVE-2018-8027: Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
nvd
CVE-2019-0194P3HIGHCVSS 7.5≥ 2.0.0, ≤ 2.19.0≥ 2.21.0, ≤ 2.21.3+2 more2019-04-30
CVE-2019-0194 [HIGH] CWE-22 CVE-2019-0194: Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
nvd
CVE-2014-0003P3HIGHCVSS 7.5≤ 2.11.3v1.0.0+26 more2014-03-21
CVE-2014-0003 [HIGH] CWE-264 CVE-2014-0003: The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
nvd
CVE-2026-55994P3HIGHCVSS 7.5≥ 4.17.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-55994 [HIGH] CWE-20 CVE-2026-55994: Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The camel-iggy consumer mapped the user-headers of inbound Iggy messages into the Camel Exchange header map without applying any HeaderFilterStrategy (IggyFetchRecords copied the mes
nvd
CVE-2026-46457P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46457 [HIGH] CWE-20 CVE-2026-46457: Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component ma Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured (NatsConfiguration). With no inFilter, inFilterPattern or inFilterStartsWith set, D
nvd
CVE-2026-46585P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46585 [HIGH] CWE-20 CVE-2026-46585: Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for HEADER_RETURN_LUCENE_DOCS). Because these names do not sta
nvd
CVE-2026-46592P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46592 [HIGH] CWE-20 CVE-2026-46592: Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE)
nvd
CVE-2013-4330P3MEDIUMCVSS 6.8≤ 2.9.6v1.0.0+46 more2013-10-04
CVE-2013-4330 [MEDIUM] CWE-94 CVE-2013-4330: Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote atta Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
nvd
CVE-2020-11994P3HIGHCVSS 7.5≥ 2.22.0, ≤ 2.22.5≥ 2.23.0, ≤ 2.23.4+4 more2020-07-08
CVE-2020-11994 [HIGH] CWE-74 CVE-2020-11994: Server-Side Template Injection and arbitrary file disclosure on Camel templating components Server-Side Template Injection and arbitrary file disclosure on Camel templating components
nvd
CVE-2026-40048P3HIGHCVSS 7.8≥ 4.18.0, < 4.18.2v4.19.02026-04-27
CVE-2026-40048 [HIGH] CWE-502 CVE-2026-40048: The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effe
nvd
CVE-2026-46588P3HIGHCVSS 7.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46588 [HIGH] CWE-20 CVE-2026-46588: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2026-46587P3HIGHCVSS 7.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46587 [HIGH] CWE-20 CVE-2026-46587: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2026-49042P3HIGHCVSS 7.3≥ 4.8.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-49042 [HIGH] CWE-20 CVE-2026-49042: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8. Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2024-22371P3HIGHCVSS 7.5≥ 3.0.0, < 3.21.4≥ 4.0.0, < 4.0.4+2 more2024-02-26
CVE-2024-22371 [HIGH] CWE-922 CVE-2024-22371: Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCr Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version
nvd
CVE-2026-49097P3MEDIUMCVSS 6.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49097 [MEDIUM] CWE-20 CVE-2026-49097: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel IRC component. The camel-irc producer chooses the destination of an outgoing IRC message from the irc.sendTo Exchange header (the constant IrcConstants.IRC_SEND_TO, value irc.sendTo); when that h
nvd
CVE-2024-22369P3HIGHCVSS 7.8≥ 3.0.0, < 3.21.4≥ 4.0.0, < 4.0.4+2 more2024-02-20
CVE-2024-22369 [HIGH] CWE-502 CVE-2024-22369: Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apac Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are sugg
nvd
CVE-2017-5643P3HIGHCVSS 7.4≤ 2.16.0v2.17.0+8 more2017-03-16
CVE-2017-5643 [HIGH] CWE-918 CVE-2017-5643: Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
nvd