cbcvebase.

Apache Software Foundation Apache Camel vulnerabilities

33 known vulnerabilities affecting apache_software_foundation/apache_camel.

Total CVEs
33
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH12MEDIUM8

Vulnerabilities

Page 1 of 2
CVE-2025-27636P2MEDIUMCVSS 5.6ExploitedPoC≥ 3.18.0, < 4.14.6≥ 4.15.0, < 4.18.22025-03-09
CVE-2025-27636 [MEDIUM] CWE-178 CVE-2025-27636: Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue a Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is
nvd
CVE-2026-33453P1CRITICALCVSS 10.0PoC≥ 4.14.0, ≤ 4.14.5≥ 4.18.0, < 4.18.1+1 more2026-04-27
CVE-2026-33453 [CRITICAL] CWE-915 CVE-2026-33453: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apac Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap c
nvd
CVE-2026-40860P2CRITICALCVSS 9.8≥ 3.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-04-27
CVE-2026-40860 [CRITICAL] CWE-502 CVE-2026-40860: JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, des JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enab
nvd
CVE-2026-46454P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46454 [CRITICAL] CWE-20 CVE-2026-46454: Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd componen Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD client directly onto the Camel mess
nvd
CVE-2026-40047P2CRITICALCVSS 9.1≥ 4.15.0, < 4.18.32026-07-06
CVE-2026-40047 [CRITICAL] CWE-88 CVE-2026-40047: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through th
nvd
CVE-2016-8749P2CRITICALCVSS 9.8v2.16.0 to 2.16.4v2.17.0 to 2.17.4+2 more2017-03-28
CVE-2016-8749 [CRITICAL] CWE-502 CVE-2016-8749: Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Executio Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
nvd
CVE-2024-23114P2CRITICALCVSS 9.8≥ 3.0.0, < 3.21.4≥ 3.22.0, < 3.22.1+2 more2024-02-20
CVE-2024-23114 [CRITICAL] CWE-502 CVE-2024-23114: Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRep Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.
nvd
CVE-2026-48204P2CRITICALCVSS 9.8≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-48204 [CRITICAL] CWE-20 CVE-2026-48204: Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gr Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConsta
nvd
CVE-2026-46455P2CRITICALCVSS 9.8≥ 4.18.0, < 4.18.3≥ 4.19.0, < 4.21.02026-07-06
CVE-2026-46455 [CRITICAL] CWE-613 CVE-2026-46455: Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloa Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. Keycloak's TokenVerifier.withChecks(...) appends to an initi
nvd
CVE-2026-48203P2CRITICALCVSS 9.1≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-48203 [CRITICAL] CWE-20 CVE-2026-48203: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. The camel-solr producer copies Exchange message headers whose names begin with the SolrParam. prefix into the parameters of the Solr request,
nvd
CVE-2026-43865P3HIGHCVSS 8.1≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-43865 [HIGH] CWE-502 CVE-2026-43865: Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-haze Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied HazelcastInstance, hazelcastConfigUri, or re
nvd
CVE-2026-40859P3HIGHCVSS 8.1≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-40859 [HIGH] CWE-502 CVE-2026-40859: Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component des Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream) This deserialization path is rea
nvd
CVE-2017-12634P3CRITICALCVSS 9.8v2.19.0 to 2.19.3v2.20.0+1 more2017-11-15
CVE-2017-12634 [CRITICAL] CWE-502 CVE-2017-12634: The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
nvd
CVE-2017-3159P3CRITICALCVSS 9.8v2.17.0 to 2.17.4v2.18.0 to 2.18.1+1 more2017-03-07
CVE-2017-3159 [CRITICAL] CWE-502 CVE-2017-3159: Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
nvd
CVE-2017-12633P3CRITICALCVSS 9.8v2.19.0 to 2.19.3v2.20.0+1 more2017-11-15
CVE-2017-12633 [CRITICAL] CWE-502 CVE-2017-12633: The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
nvd
CVE-2026-42527P3HIGHCVSS 8.1≥ 4.14.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-42527 [HIGH] CWE-502 CVE-2026-42527: Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter patt Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a recursive 'java.**' glob that admits
nvd
CVE-2018-8027P3CRITICALCVSS 9.8v2.20.0 to 2.20.3v2.21.02018-07-31
CVE-2018-8027 [CRITICAL] CWE-611 CVE-2018-8027: Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
nvd
CVE-2026-46457P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46457 [HIGH] CWE-20 CVE-2026-46457: Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component ma Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured (NatsConfiguration). With no inFilter, inFilterPattern or inFilterStartsWith set, D
nvd
CVE-2026-46592P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46592 [HIGH] CWE-20 CVE-2026-46592: Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE)
nvd
CVE-2026-40048P3HIGHCVSS 7.8≥ 4.18.0, < 4.18.3≥ 4.19.0, < 4.21.02026-04-27
CVE-2026-40048 [HIGH] CWE-502 CVE-2026-40048: The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effe
nvd
Apache Software Foundation Apache Camel vulnerabilities | cvebase