Camel
86 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Camel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Camel CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 9 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 34 |
| 2026-08 | 8 |
| 2026-09 | 3 |
Severity
How the 86 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical30
- High34
- Medium19
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Camel.
- CVE-2026-80354Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace8.1
- CVE-2026-80351Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod9.8
- CVE-2026-80352Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects9.8
- CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes9.8
- CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection9.8
- CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy5.3
- CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted7.5
- CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result7.5
- CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir9.1
- CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir5.5
- CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled6.5
- CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input7.3
- CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters7.3
- CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder7.3
Product grouping is registry-driven, with AI assist and human review. How it works