CVE-2026-25747
- EPSS 0.07%
- Veröffentlicht 23.02.2026 08:45:45
- Zuletzt bearbeitet 26.02.2026 22:20:46
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any O...
CVE-2026-23552
- EPSS 0.04%
- Veröffentlicht 23.02.2026 08:45:36
- Zuletzt bearbeitet 26.02.2026 16:46:16
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keyc...
CVE-2025-66169
- EPSS 0.03%
- Veröffentlicht 14.01.2026 11:45:20
- Zuletzt bearbeitet 16.01.2026 14:29:11
Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS...
CVE-2025-30177
- EPSS 0.83%
- Veröffentlicht 01.04.2025 12:15:15
- Zuletzt bearbeitet 15.04.2025 13:00:12
Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10...
CVE-2025-29891
- EPSS 0.12%
- Veröffentlicht 12.03.2025 14:42:59
- Zuletzt bearbeitet 02.04.2025 20:37:07
Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS a...
CVE-2025-27636
- EPSS 47.77%
- Veröffentlicht 09.03.2025 13:15:34
- Zuletzt bearbeitet 23.06.2025 18:54:52
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to v...
CVE-2024-22371
- EPSS 0.68%
- Veröffentlicht 26.02.2024 16:27:56
- Zuletzt bearbeitet 25.04.2025 18:56:25
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through...
CVE-2024-23114
- EPSS 1.04%
- Veröffentlicht 20.02.2024 15:15:10
- Zuletzt bearbeitet 02.04.2025 20:19:16
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Ap...
CVE-2024-22369
- EPSS 4.75%
- Veröffentlicht 20.02.2024 15:15:10
- Zuletzt bearbeitet 02.04.2025 20:17:04
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to ...
CVE-2023-34442
- EPSS 0.04%
- Veröffentlicht 10.07.2023 16:15:52
- Zuletzt bearbeitet 21.11.2024 08:07:15
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X thro...