Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.68% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel IRC component. The camel-irc producer chooses the destination of an outgoing IRC message from the irc.sendTo Exchange header (the constant… | |
| Analizada | Media (6.5) | 0.68% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name and its topic - into the CamelDaprPubSubName and… | |
| Analizada | Media (5.3) | 0.55% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers read their operation parameters - the issue key, project key, transition id, summary, type, assignee, components, watchers, link type, work-log minutes and others - from… | |
| Analizada | Crítica (9.1) | 0.60% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operation parameters - the resolver to query, the name or domain to look up, the record type and class, and the search term - from Exchange message headers whose constant values… | |
| Analizada | Crítica (9.8) | 0.73% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The… | |
| Analizada | Crítica (9.1) | 0.60% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. The camel-solr producer copies Exchange message headers whose names begin with the SolrParam. prefix into the… | |
| Analizada | Alta (7.5) | 0.86% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket component. The camel-vertx-websocket consumer mapped inbound WebSocket query and path parameters into the Camel Exchange header map without applying… | |
| Analizada | Alta (7.5) | 0.63% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values… | |
| Analizada | Alta (8.2) | 0.55% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property… | |
| Analizada | Alta (8.8) | 0.84% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the… | |
| Analizada | Alta (7.5) | 0.63% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for… | |
| Analizada | Baja (3.7) | 0.56% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component. The camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a… | |
| Analizada | Alta (7.5) | 0.66% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured (NatsConfiguration). With no inFilter,… | |
| Analizada | Crítica (9.8) | 0.79% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrategy configured only an outbound filter (setOutFilterPattern, which blocks Camel*,… | |
| Analizada | Crítica (9.8) | 0.69% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. Keycloak's… | |
| Analizada | Crítica (9.8) | 0.83% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD… | |
| Analizada | Media (5.3) | 0.55% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (which Elasticsearch operation to… | |
| Analizada | Crítica (9.8) | 0.93% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that metadata back from the configured AWS… | |
| Analizada | Alta (7.3) | 0.65% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() whenever the mapJmsMessage option… | |
| Analizada | Alta (8.1) | 0.98% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied… | |
| Analizada | Alta (8.1) | 0.67% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a… | |
| Analizada | Alta (8.1) | 0.89% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter… | |
| Analizada | Crítica (9.1) | 2.4% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom… | |
| Aplazada | Alta (8.1) | 0.39% | — | Apache Camel KAI | 21/5/2026 | 23/7/2026 | (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace.… | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Apache Camel | 19/5/2026 | 15/7/2026 | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) only filter outbound… |