Apache
Apache Camel: vulnerabilidades y CVE
Apache Camel tiene 89 vulnerabilidades publicadas, 61 de ellas en los últimos 12 meses. 30 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE89
Últimos 12 meses61
Críticas30
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51858 | Sin puntuar | 0.25% | — | 30 sept 2026 | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary. |
| CVE-2026-51857 | Sin puntuar | 0.22% | — | 30 sept 2026 | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary. |
| CVE-2026-80354 | Alta (8.1) | 0.50% | — | 10 sept 2026 | Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace,… |
| CVE-2026-80352 | Crítica (9.8) | 0.84% | — | 10 sept 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes… |
| CVE-2026-80351 | Crítica (9.8) | 1.0% | — | 10 sept 2026 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows… |
| CVE-2026-78329 | Crítica (9.8) | 0.74% | — | 24 ago 2026 | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted… |
| CVE-2026-71300 | Crítica (9.8) | 0.74% | — | 24 ago 2026 | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The… |
| CVE-2026-66908 | Alta (7.5) | 0.61% | — | 24 ago 2026 | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT… |
| CVE-2026-66907 | Alta (7.5) | 0.81% | — | 24 ago 2026 | Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage… |
| CVE-2026-66906 | Crítica (9.1) | 0.78% | — | 24 ago 2026 | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The… |
| CVE-2026-63621 | Media (5.3) | 0.59% | — | 24 ago 2026 | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps… |
| CVE-2026-60093 | Media (5.5) | 0.24% | — | 24 ago 2026 | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The… |
| CVE-2026-59230 | Media (6.5) | 0.68% | — | 24 ago 2026 | Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-mail component ships a MimeMultipart… |
| CVE-2026-49042 | Alta (7.3) | 0.69% | — | 6 jul 2026 | Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes… |
| CVE-2026-46588 | Alta (7.3) | 0.69% | — | 6 jul 2026 | Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8,… |
| CVE-2026-46587 | Alta (7.3) | 0.69% | — | 6 jul 2026 | Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8,… |
| CVE-2026-56140 | Crítica (9.8) | 0.74% | — | 6 jul 2026 | Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling… |
| CVE-2026-56139 | Media (5.3) | 0.57% | — | 6 jul 2026 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the… |
| CVE-2026-55994 | Alta (7.5) | 0.63% | — | 6 jul 2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The camel-iggy consumer mapped the user-headers… |
| CVE-2026-55993 | Alta (7.5) | 0.86% | — | 6 jul 2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket… |
| CVE-2026-53913 | Crítica (9.8) | 1.1% | — | 6 jul 2026 | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route… |
| CVE-2026-49365 | Media (5.3) | 0.57% | — | 6 jul 2026 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to… |
| CVE-2026-49099 | Media (5.3) | 0.52% | — | 6 jul 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The… |
| CVE-2026-49098 | Media (5.3) | 0.61% | — | 6 jul 2026 | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer can override its… |
| CVE-2026-49097 | Media (6.5) | 0.68% | — | 6 jul 2026 | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel IRC component. The camel-irc producer chooses the destination… |
| CVE-2026-49086 | Media (6.5) | 0.68% | — | 6 jul 2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound… |
| CVE-2026-48206 | Media (5.3) | 0.55% | — | 6 jul 2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers read their operation parameters - the issue key, project key, transition… |
| CVE-2026-48205 | Crítica (9.1) | 0.60% | — | 6 jul 2026 | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operation parameters - the resolver to query, the name or domain to look up,… |
| CVE-2026-48204 | Crítica (9.8) | 0.73% | — | 6 jul 2026 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation… |
| CVE-2026-48203 | Crítica (9.1) | 0.60% | — | 6 jul 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. The… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.