cbcvebase.

Apache Camel vulnerabilities

74 known vulnerabilities affecting apache/camel.

Total CVEs
74
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL25HIGH31MEDIUM16LOW2

Vulnerabilities

Page 4 of 4
CVE-2025-30177P3MEDIUMCVSS 6.5≥ 4.8.0, < 4.8.6≥ 4.10.0, < 4.10.32025-04-01
CVE-2025-30177 [MEDIUM] CWE-164 CVE-2025-30177: Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditio Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injec
nvd
CVE-2026-49086P3MEDIUMCVSS 6.5≥ 4.12.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49086 [MEDIUM] CWE-20 CVE-2026-49086: Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name and its topic - into the CamelDaprPubSubName and CamelDaprTopic Exchange headers. These two
nvd
CVE-2015-0263P3MEDIUMCVSS 5.0≤ 2.13.3v2.14.0+1 more2015-06-03
CVE-2015-0263 [MEDIUM] CVE-2015-0263: XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.ja XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
nvd
CVE-2015-0264P3MEDIUMCVSS 5.0≤ 2.13.3v2.14.0+1 more2015-06-03
CVE-2015-0264 [MEDIUM] CVE-2015-0264: Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
nvd
CVE-2018-8041P4MEDIUMCVSS 5.3≥ 2.20.0, ≤ 2.20.3≥ 2.21.0, ≤ 2.21.1+1 more2018-09-17
CVE-2018-8041 [MEDIUM] CWE-22 CVE-2018-8041: Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path tr Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
nvd
CVE-2026-49098P3MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49098 [MEDIUM] CWE-20 CVE-2026-49098: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer can override its configured target topic at runtime from the kafka.OVERRIDE_TOPIC Exchange header: KafkaProducer.evaluateTopic() returns the header value
nvd
CVE-2026-48206P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-48206 [MEDIUM] CWE-20 CVE-2026-48206: Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers read their operation parameters - the issue key, project key, transition id, summary, type, assignee, components, watchers, link type, work-log minutes and others - from Exchange message headers. The heade
nvd
CVE-2026-49099P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49099 [MEDIUM] CWE-74 CVE-2026-49099: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The camel-salesforce producer resolves its operation parameters - the SOQL query, the SOSL search, the target SObject name and id, the Apex REST URL an
nvd
CVE-2026-46453P4MEDIUMCVSS 5.3≥ 4.3.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46453 [MEDIUM] CWE-20 CVE-2026-46453: Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (which Elasticsearch operation to run), INDEX_NAME, INDEX_SETTINGS
nvd
CVE-2026-56139P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-56139 [MEDIUM] CWE-209 CVE-2026-56139: Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false, whereas the other Camel HTTP server components (camel-
nvd
CVE-2026-49365P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49365 [MEDIUM] CWE-209 CVE-2026-49365: Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTT Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false because the backing field was an uninitialised pri
nvd
CVE-2025-66169P4MEDIUMCVSS 5.3≥ 4.10.0, < 4.10.8≥ 4.14.0, < 4.14.3+1 more2026-01-14
CVE-2025-66169 [MEDIUM] CWE-89 CVE-2025-66169: Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Cam Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
nvd
CVE-2026-46584P4LOWCVSS 3.7≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46584 [LOW] CWE-20 CVE-2026-46584: Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component. The camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a per-message JavaMail sender with those values
nvd
CVE-2023-34442P4LOWCVSS 3.3≥ 3.0.0, < 3.14.9≥ 3.18.0, < 3.18.8+2 more2023-07-10
CVE-2023-34442 [LOW] CWE-200 CVE-2023-34442: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundati Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3. Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x up
nvd