Apache Camel
52 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Apache Camel, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Apache Camel CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 5 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 22 |
| 2026-08 | 8 |
| 2026-09 | 0 |
Severity
How the 52 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical21
- High19
- Medium11
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache Camel.
- CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
- CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
- CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
- CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
- CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
- CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
- CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
- CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
- CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
- CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3
- CVE-2026-43867Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter9.8
- CVE-2026-49365Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients5.3
- CVE-2026-49098Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic5.3
Product grouping is registry-driven, with AI assist and human review. How it works