Camel
This hub aggregates every CVE we track for Camel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
86
CVEs tracked
30
Critical
34
High
0
In CISA KEV
Severity distribution
HIGH34CRITICAL30MEDIUM19LOW3
Monthly trend
0
0
0
0
0
2
1
0
0
0
0
0
0
0
0
1
2
0
9
1
0
34
8
3
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Camel.
- CVE-2026-80354Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace8.1
- CVE-2026-80351Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod9.8
- CVE-2026-80352Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects9.8
- CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
- CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
- CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
- CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
- CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
- CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
- CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
- CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
- CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
- CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3
Product normalization is registry-driven with AI assist and human review. How it works