CVE-2026-78329Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-71300Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-63621Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Trung bình CVE-2026-66908Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Cao CVE-2026-66907Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Cao CVE-2026-66906Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-60093Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Trung bình CVE-2026-59230Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 24/08/2026 Mức độ nghiêm trọng Trung bình CVE-2026-46588Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-46587Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-49042Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-43866Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-43867Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-49365Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-49098Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-49097Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-48204Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-48203Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-46592Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-46591Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169) Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-46590Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048) Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-46457Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-46456Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-46455Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-46454Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-46453Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-43865Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-42527Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-40859Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Cao CVE-2026-40047Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 06/07/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-47323Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 19/05/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-27172Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 27/04/2026 Mức độ nghiêm trọng Cao CVE-2026-33453Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 27/04/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-33454Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant) Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 27/04/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-40858Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 27/04/2026 Mức độ nghiêm trọng Cao CVE-2026-40860Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 27/04/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2026-25747Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB Tình trạng khai thác Khai thác công khai Bản vá CóNgày phát hành 23/02/2026 Mức độ nghiêm trọng Cao CVE-2026-23552Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Tình trạng khai thác Khai thác công khai Bản vá CóNgày phát hành 23/02/2026 Mức độ nghiêm trọng Nghiêm trọng CVE-2025-30177Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 01/04/2025 Mức độ nghiêm trọng Trung bình CVE-2025-29891Apache Camel: Camel Message Header Injection through request parameters Tình trạng khai thác Khai thác công khai Bản vá CóNgày phát hành 12/03/2025 Mức độ nghiêm trọng Trung bình CVE-2025-27636Apache Camel: Camel Message Header Injection via Improper Filtering Tình trạng khai thác Khai thác công khai Bản vá CóNgày phát hành 09/03/2025 Mức độ nghiêm trọng Trung bình CVE-2024-22371Apache Camel issue on ExchangeCreatedEvent Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 26/02/2024 Mức độ nghiêm trọng Thấp CVE-2024-23114Apache Camel: Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 20/02/2024 Mức độ nghiêm trọng Nghiêm trọng CVE-2024-22369Apache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepository Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóNgày phát hành 20/02/2024 Mức độ nghiêm trọng Cao CVE-2018-8041Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 17/09/2018 Mức độ nghiêm trọng Chưa rõ CVE-2018-8027Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 31/07/2018 Mức độ nghiêm trọng Chưa rõ CVE-2017-12633Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 15/11/2017 Mức độ nghiêm trọng Chưa rõ CVE-2017-12634Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 15/11/2017 Mức độ nghiêm trọng Chưa rõ CVE-2016-8749Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 28/03/2017 Mức độ nghiêm trọng Chưa rõ CVE-2017-5643Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 16/03/2017 Mức độ nghiêm trọng Chưa rõ CVE-2017-3159Tình trạng khai thác Chưa xác nhận Bản vá Chưa xác nhận Ngày phát hành 07/03/2017 Mức độ nghiêm trọng Chưa rõ