Apache camel
This hub aggregates every CVE we track for Apache camel, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
52
CVEs tracked
21
Critical
19
High
0
In CISA KEV
Severity distribution
CRITICAL21HIGH19MEDIUM11LOW1
Monthly trend
0
0
0
0
0
2
1
0
0
0
0
0
0
0
0
0
1
0
5
1
0
22
8
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache camel.
- CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
- CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
- CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
- CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
- CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
- CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
- CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
- CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
- CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
- CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3
- CVE-2026-43867Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter9.8
- CVE-2026-49365Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients5.3
- CVE-2026-49098Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic5.3
Product normalization is registry-driven with AI assist and human review. How it works