CVE-2026-80354
- EPSS 0.22%
- Veröffentlicht 10.09.2026 07:43:23
- Zuletzt bearbeitet 14.09.2026 19:57:26
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets bel...
CVE-2026-80351
- EPSS 0.4%
- Veröffentlicht 10.09.2026 07:42:57
- Zuletzt bearbeitet 14.09.2026 19:56:49
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository conte...
CVE-2026-80352
- EPSS 0.33%
- Veröffentlicht 10.09.2026 07:41:33
- Zuletzt bearbeitet 14.09.2026 19:57:07
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling ...
CVE-2026-78329
- EPSS 0.16%
- Veröffentlicht 24.08.2026 16:22:17
- Zuletzt bearbeitet 27.08.2026 18:19:40
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted its headerFilterStrategy fi...
CVE-2026-71300
- EPSS 0.37%
- Veröffentlicht 24.08.2026 16:21:17
- Zuletzt bearbeitet 27.08.2026 18:07:55
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer sel...
CVE-2026-63621
- EPSS 0.22%
- Veröffentlicht 24.08.2026 16:17:26
- Zuletzt bearbeitet 27.08.2026 20:13:13
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes on...
CVE-2026-66908
- EPSS 0.37%
- Veröffentlicht 24.08.2026 16:14:18
- Zuletzt bearbeitet 28.08.2026 17:51:02
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured thr...
CVE-2026-66907
- EPSS 0.39%
- Veröffentlicht 24.08.2026 16:13:04
- Zuletzt bearbeitet 27.08.2026 20:35:51
Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google ...
CVE-2026-66906
- EPSS 0.38%
- Veröffentlicht 24.08.2026 16:12:09
- Zuletzt bearbeitet 27.08.2026 20:34:24
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can down...
CVE-2026-60093
- EPSS 0.19%
- Veröffentlicht 24.08.2026 16:11:23
- Zuletzt bearbeitet 27.08.2026 17:55:53
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component c...