Apache Software Foundation Apache Camel K vulnerabilities
4 known vulnerabilities affecting apache_software_foundation/apache_camel_k.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-80351P2CRITICALCVSS 9.8≥ 2.0.0, < 2.9.3≥ 2.10.1, < 2.10.22026-09-10
CVE-2026-80351 [CRITICAL] CWE-95 CVE-2026-80351: Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K.
An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbit
nvd
CVE-2026-80352P2CRITICALCVSS 9.8≥ 2.0.0, < 2.9.3≥ 2.10.1, < 2.10.22026-09-10
CVE-2026-80352 [CRITICAL] CWE-94 CVE-2026-80352: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.
This issue affects Apache Camel K:
nvd
CVE-2026-45760P3HIGHCVSS 8.1≥ 2.0.0, < 2.8.1≥ 2.9.0, < 2.9.2+1 more2026-05-21
CVE-2026-45760 [HIGH] CWE-610 CVE-2026-45760: (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through Use
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace.
This issue affects Apache Camel
nvd
CVE-2026-80354P3HIGHCVSS 8.1≥ 2.0.0, < 2.9.3≥ 2.10.1, < 2.10.22026-09-10
CVE-2026-80354 [HIGH] CWE-639 CVE-2026-80354: Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorizatio
Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components.
This issue affects Apache Camel K: from 2.0.0 before 2.9.
nvd