cbcvebase.

Apache Software Foundation Apache Camel vulnerabilities

33 known vulnerabilities affecting apache_software_foundation/apache_camel.

Total CVEs
33
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH12MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2026-46588P3HIGHCVSS 7.3≤ 4.14.7≥ 4.15.0, ≤ 4.18.2+1 more2026-07-06
CVE-2026-46588 [HIGH] CWE-20 CVE-2026-46588: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2026-46587P3HIGHCVSS 7.3≤ 4.14.7≥ 4.15.0, ≤ 4.18.2+1 more2026-07-06
CVE-2026-46587 [HIGH] CWE-20 CVE-2026-46587: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2026-49042P3HIGHCVSS 7.3≥ 4.8.0, ≤ 4.18.2≥ 4.19.0, ≤ 4.20.02026-07-06
CVE-2026-49042 [HIGH] CWE-20 CVE-2026-49042: Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8. Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.
nvd
CVE-2024-22371P3HIGHCVSS 7.5≥ 3.21.x, ≤ 3.21.3≥ 3.22.x, ≤ 3.22.0+2 more2024-02-26
CVE-2024-22371 [HIGH] CWE-922 CVE-2024-22371: Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCr Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version
nvd
CVE-2026-49097P3MEDIUMCVSS 6.5≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49097 [MEDIUM] CWE-20 CVE-2026-49097: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel IRC component. The camel-irc producer chooses the destination of an outgoing IRC message from the irc.sendTo Exchange header (the constant IrcConstants.IRC_SEND_TO, value irc.sendTo); when that h
nvd
CVE-2024-22369P3HIGHCVSS 7.8≥ 4.0.0, < 4.14.7≥ 4.15.0, < 4.18.2+1 more2024-02-20
CVE-2024-22369 [HIGH] CWE-502 CVE-2024-22369: Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apac Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are sugg
nvd
CVE-2017-5643P3HIGHCVSS 7.4v2.17.0 to 2.17.5v2.18.0 to 2.18.2+1 more2017-03-16
CVE-2017-5643 [HIGH] CWE-918 CVE-2017-5643: Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
nvd
CVE-2025-30177P3MEDIUMCVSS 6.5≥ 4.10.0, < 4.10.3≥ 4.8.0, < 4.8.62025-04-01
CVE-2025-30177 [MEDIUM] CWE-164 CVE-2025-30177: Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditio Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injec
nvd
CVE-2018-8041P4MEDIUMCVSS 5.3vCamel 2.20.0 to 2.20.3, Camel 2.21.0 to 2.21.1 and Camel 2.22.02018-09-17
CVE-2018-8041 [MEDIUM] CWE-22 CVE-2018-8041: Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path tr Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
nvd
CVE-2026-49098P3MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49098 [MEDIUM] CWE-20 CVE-2026-49098: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer can override its configured target topic at runtime from the kafka.OVERRIDE_TOPIC Exchange header: KafkaProducer.evaluateTopic() returns the header value
nvd
CVE-2026-46453P4MEDIUMCVSS 5.3≥ 4.3.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46453 [MEDIUM] CWE-20 CVE-2026-46453: Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (which Elasticsearch operation to run), INDEX_NAME, INDEX_SETTINGS
nvd
CVE-2026-49365P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49365 [MEDIUM] CWE-209 CVE-2026-49365: Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTT Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. This option defaulted to false because the backing field was an uninitialised pri
nvd
CVE-2025-66169P4MEDIUMCVSS 5.3≥ 4.10.0, < 4.14.8≥ 4.15.0, < 4.18.3+1 more2026-01-14
CVE-2025-66169 [MEDIUM] CWE-89 CVE-2025-66169: Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Cam Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
nvd
Apache Software Foundation Apache Camel vulnerabilities | cvebase