VYPR

Camel

by Apache

Source repositories

CVEs (75)

  • CVE-2026-46590HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and…

  • CVE-2026-46585HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and…

  • CVE-2026-46457HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured…

  • CVE-2026-46456CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrategy configured only an outbound filter…

  • CVE-2026-46455CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.00

    Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL…

  • CVE-2026-46454CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire…

  • CVE-2026-46453MedJul 6, 2026
    risk 0.00cvss 5.3epss 0.01

    Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advanced query body),…

  • CVE-2026-43867CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that…

  • CVE-2026-43865HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself -…

  • CVE-2026-42527HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the…

  • CVE-2015-0264Jun 3, 2015
    risk 0.00cvss epss 0.07

    Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath…

  • CVE-2015-0263Jun 3, 2015
    risk 0.00cvss epss 0.08

    XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

  • CVE-2014-0003Mar 21, 2014
    risk 0.00cvss epss 0.07

    The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

  • CVE-2014-0002Mar 21, 2014
    risk 0.00cvss epss 0.33

    The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to…

  • CVE-2013-4330Oct 4, 2013
    risk 0.00cvss epss 0.09

    Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

Page 4 of 4