CVE Tools

Apache Camel

52 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apache Camel, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Camel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Camel CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-032
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-045
2026-051
2026-060
2026-0722
2026-088
2026-090

Severity

How the 52 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2140%
  • High1937%
  • Medium1121%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache Camel.

  1. CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
  2. CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
  3. CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
  4. CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
  5. CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
  6. CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
  7. CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
  8. CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
  9. CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
  10. CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
  11. CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
  12. CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3
  13. CVE-2026-43867Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter9.8
  14. CVE-2026-49365Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients5.3
  15. CVE-2026-49098Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store