VYPR

Camel Karavan

by Apache

CVEs (2)

  • CVE-2026-103413HigOct 9, 2026
    risk 0.50cvss 8.8epss —

    Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting…

  • CVE-2026-103412HigOct 9, 2026
    risk 0.50cvss 8.8epss —

    Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git…