CVE Tools

Camel

86 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Camel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Camel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Camel CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-032
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-022
2026-030
2026-049
2026-051
2026-060
2026-0734
2026-088
2026-093

Severity

How the 86 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical3035%
  • High3440%
  • Medium1922%
  • Low33%

Latest CVEs

The 15 most recently published vulnerabilities affecting Camel.

  1. CVE-2026-80354Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace8.1
  2. CVE-2026-80351Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod9.8
  3. CVE-2026-80352Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects9.8
  4. CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
  5. CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
  6. CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
  7. CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
  8. CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
  9. CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
  10. CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
  11. CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
  12. CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
  13. CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
  14. CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
  15. CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store