{"schema_version":1,"title":"Apache Camel vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 40 vulnerabilities in Apache Camel: 0 in the last 7 days and 36 in the last 90 days, 14 of them critical and 0 exploited in the wild. The most recent, CVE-2026-78329, was published on 24 August 2026.","url":"https://junglewise.ai/threats/technologies/camel","json_url":"https://junglewise.ai/threats/technologies/camel.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/camel","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":40,"critical":14,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":36,"last_365_days":40},"latest":[{"cve":"CVE-2026-78329","cvss":9.8,"epss":0.0074,"slug":"cve-2026-78329-apache-camel-undertow-header-filter-bypass-in-endpoint-routes","title":"Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, f","severity":"critical","exploited":false,"published_at":"2026-08-24T17:18:20.23+00:00","url":"https://junglewise.ai/threats/cve-2026-78329-apache-camel-undertow-header-filter-bypass-in-endpoint-routes"},{"cve":"CVE-2026-71300","cvss":9.8,"epss":0.0074,"slug":"cve-2026-71300-apache-camel-atmosphere-websocket-header-injection-in-producer","title":"Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 befor","severity":"critical","exploited":false,"published_at":"2026-08-24T17:18:16.997+00:00","url":"https://junglewise.ai/threats/cve-2026-71300-apache-camel-atmosphere-websocket-header-injection-in-producer"},{"cve":"CVE-2026-66908","cvss":7.5,"epss":0.0061,"slug":"cve-2026-66908-apache-camel-platform-http-main-jwt-authentication-bypass","title":"Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.","severity":"high","exploited":false,"published_at":"2026-08-24T17:18:06.53+00:00","url":"https://junglewise.ai/threats/cve-2026-66908-apache-camel-platform-http-main-jwt-authentication-bypass"},{"cve":"CVE-2026-66906","cvss":9.1,"epss":0.0078,"slug":"cve-2026-66906-apache-camel-azure-storage-blob-path-traversal-in","title":"Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.","severity":"critical","exploited":false,"published_at":"2026-08-24T17:18:06.147+00:00","url":"https://junglewise.ai/threats/cve-2026-66906-apache-camel-azure-storage-blob-path-traversal-in"},{"cve":"CVE-2026-63621","cvss":5.3,"epss":0.0059,"slug":"cve-2026-63621-apache-camel-knative-header-injection-in-structured-content-mode","title":"Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-24T17:17:58.41+00:00","url":"https://junglewise.ai/threats/cve-2026-63621-apache-camel-knative-header-injection-in-structured-content-mode"},{"cve":"CVE-2026-60093","cvss":5.5,"epss":0.0024,"slug":"cve-2026-60093-apache-camel-azure-storage-datalake-path-traversal-in","title":"Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before","severity":"medium","exploited":false,"published_at":"2026-08-24T17:17:29.783+00:00","url":"https://junglewise.ai/threats/cve-2026-60093-apache-camel-azure-storage-datalake-path-traversal-in"},{"cve":"CVE-2026-59230","cvss":6.5,"epss":0.0068,"slug":"cve-2026-59230-apache-camel-mail-header-injection-via-headersinline","title":"Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4","severity":"medium","exploited":false,"published_at":"2026-08-24T17:17:28.383+00:00","url":"https://junglewise.ai/threats/cve-2026-59230-apache-camel-mail-header-injection-via-headersinline"},{"cve":"CVE-2026-49042","cvss":7.3,"epss":0.0069,"slug":"cve-2026-49042-apache-camel-header-injection-in-ai-tool-components","title":"Apache Camel header injection in AI tool components","severity":"high","exploited":false,"published_at":"2026-07-06T11:16:29.607+00:00","url":"https://junglewise.ai/threats/cve-2026-49042-apache-camel-header-injection-in-ai-tool-components"},{"cve":"CVE-2026-46588","cvss":7.3,"epss":0.0069,"slug":"cve-2026-46588-apache-camel-improper-input-validation-in-camel-couchdb","title":"Apache Camel improper input validation in camel-couchdb","severity":"high","exploited":false,"published_at":"2026-07-06T11:16:28.777+00:00","url":"https://junglewise.ai/threats/cve-2026-46588-apache-camel-improper-input-validation-in-camel-couchdb"},{"cve":"CVE-2026-46587","cvss":7.3,"epss":0.0069,"slug":"cve-2026-46587-apache-camel-improper-input-validation-in-camel-couchbase","title":"Apache Camel improper input validation in camel-couchbase","severity":"high","exploited":false,"published_at":"2026-07-06T11:16:28.677+00:00","url":"https://junglewise.ai/threats/cve-2026-46587-apache-camel-improper-input-validation-in-camel-couchbase"},{"cve":"CVE-2026-56139","cvss":5.3,"epss":0.0057,"slug":"cve-2026-56139-apache-camel-undertow-information-disclosure-in-error-messages","title":"Apache Camel Undertow information disclosure in error messages","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:39.157+00:00","url":"https://junglewise.ai/threats/cve-2026-56139-apache-camel-undertow-information-disclosure-in-error-messages"},{"cve":"CVE-2026-55994","cvss":7.5,"epss":0.0063,"slug":"cve-2026-55994-apache-camel-ssrf-and-information-disclosure-in-iggy-component","title":"Apache Camel SSRF and Information Disclosure in Iggy component","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:39.033+00:00","url":"https://junglewise.ai/threats/cve-2026-55994-apache-camel-ssrf-and-information-disclosure-in-iggy-component"},{"cve":"CVE-2026-55993","cvss":7.5,"epss":0.0086,"slug":"cve-2026-55993-apache-camel-ssrf-and-information-disclosure-in-atmosphere","title":"Apache Camel SSRF and information disclosure in Atmosphere Websocket","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:38.897+00:00","url":"https://junglewise.ai/threats/cve-2026-55993-apache-camel-ssrf-and-information-disclosure-in-atmosphere"},{"cve":"CVE-2026-49365","cvss":5.3,"epss":0.0057,"slug":"cve-2026-49365-apache-camel-sensitive-information-disclosure-in-netty-http","title":"Apache Camel sensitive information disclosure in Netty HTTP component","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38.627+00:00","url":"https://junglewise.ai/threats/cve-2026-49365-apache-camel-sensitive-information-disclosure-in-netty-http"},{"cve":"CVE-2026-49099","cvss":5.3,"epss":0.0052,"slug":"cve-2026-49099-apache-camel-salesforce-authorization-bypass-via-header-injection","title":"Apache Camel Salesforce authorization bypass via header injection","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38.487+00:00","url":"https://junglewise.ai/threats/cve-2026-49099-apache-camel-salesforce-authorization-bypass-via-header-injection"},{"cve":"CVE-2026-49098","cvss":5.3,"epss":0.0061,"slug":"cve-2026-49098-apache-camel-kafka-topic-redirection-via-header-injection","title":"Apache Camel Kafka topic redirection via header injection","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38.357+00:00","url":"https://junglewise.ai/threats/cve-2026-49098-apache-camel-kafka-topic-redirection-via-header-injection"},{"cve":"CVE-2026-49097","cvss":6.5,"epss":0.0068,"slug":"cve-2026-49097-apache-camel-message-redirection-in-irc-component","title":"Apache Camel message redirection in IRC component","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38.24+00:00","url":"https://junglewise.ai/threats/cve-2026-49097-apache-camel-message-redirection-in-irc-component"},{"cve":"CVE-2026-49086","cvss":6.5,"epss":0.0068,"slug":"cve-2026-49086-apache-camel-dapr-confused-deputy-in-daprpubsubconsumer","title":"Apache Camel Dapr confused deputy in DaprPubSubConsumer","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38.12+00:00","url":"https://junglewise.ai/threats/cve-2026-49086-apache-camel-dapr-confused-deputy-in-daprpubsubconsumer"},{"cve":"CVE-2026-48206","cvss":5.3,"epss":0.0055,"slug":"cve-2026-48206-apache-camel-jira-authorization-bypass-via-user-controlled","title":"Apache Camel JIRA authorization bypass via user-controlled headers","severity":"medium","exploited":false,"published_at":"2026-07-06T09:16:38+00:00","url":"https://junglewise.ai/threats/cve-2026-48206-apache-camel-jira-authorization-bypass-via-user-controlled"},{"cve":"CVE-2026-48205","cvss":9.1,"epss":0.006,"slug":"cve-2026-48205-apache-camel-ssrf-in-dns-component-via-header-injection","title":"Apache Camel SSRF in DNS component via header injection","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:37.88+00:00","url":"https://junglewise.ai/threats/cve-2026-48205-apache-camel-ssrf-in-dns-component-via-header-injection"},{"cve":"CVE-2026-48203","cvss":9.1,"epss":0.006,"slug":"cve-2026-48203-apache-camel-ssrf-and-header-injection-in-solr-component","title":"Apache Camel SSRF and header injection in Solr component","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:37.633+00:00","url":"https://junglewise.ai/threats/cve-2026-48203-apache-camel-ssrf-and-header-injection-in-solr-component"},{"cve":"CVE-2026-46726","cvss":7.5,"epss":0.0086,"slug":"cve-2026-46726-apache-camel-ssrf-and-secret-disclosure-in-vertx-websocket","title":"Apache Camel SSRF and secret disclosure in Vertx Websocket","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:37.503+00:00","url":"https://junglewise.ai/threats/cve-2026-46726-apache-camel-ssrf-and-secret-disclosure-in-vertx-websocket"},{"cve":"CVE-2026-46592","cvss":7.5,"epss":0.0063,"slug":"cve-2026-46592-apache-camel-improper-input-validation-in-cxf-soap-component","title":"Apache Camel improper input validation in CXF SOAP component","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:37.38+00:00","url":"https://junglewise.ai/threats/cve-2026-46592-apache-camel-improper-input-validation-in-cxf-soap-component"},{"cve":"CVE-2026-46591","cvss":8.2,"epss":0.0055,"slug":"cve-2026-46591-apache-camel-cypher-injection-in-neo4j-component","title":"Apache Camel Cypher injection in Neo4j component","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:37.263+00:00","url":"https://junglewise.ai/threats/cve-2026-46591-apache-camel-cypher-injection-in-neo4j-component"},{"cve":"CVE-2026-46590","cvss":8.8,"epss":0.0084,"slug":"cve-2026-46590-apache-camel-deserialization-of-untrusted-data-in-pqc-component","title":"Apache Camel deserialization of untrusted data in PQC component","severity":"high","exploited":false,"published_at":"2026-07-06T09:16:37.147+00:00","url":"https://junglewise.ai/threats/cve-2026-46590-apache-camel-deserialization-of-untrusted-data-in-pqc-component"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":7,"exploited":0,"vulnerabilities":29},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":3,"exploited":0,"vulnerabilities":7},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache Camel","slug":"camel","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"library","homepage":"https://camel.apache.org","description":"A versatile open-source integration framework for connecting applications and services with various protocols and data formats.","url":"https://junglewise.ai/threats/technologies/camel"},"most_severe":[{"cve":"CVE-2026-33453","cvss":10,"epss":0.0716,"slug":"cve-2026-33453-apache-camel-remote-code-execution-in-camel-coap-component","title":"Apache Camel remote code execution in camel-coap component","severity":"critical","exploited":false,"published_at":"2026-04-27T11:16:01.873+00:00","url":"https://junglewise.ai/threats/cve-2026-33453-apache-camel-remote-code-execution-in-camel-coap-component"},{"cve":"CVE-2026-40453","cvss":9.9,"epss":0.0189,"slug":"cve-2026-40453-apache-camel-rce-via-case-variant-header-injection-in-non-http","title":"Apache Camel RCE via case-variant header injection in non-HTTP components","severity":"critical","exploited":false,"published_at":"2026-04-27T09:16:01.493+00:00","url":"https://junglewise.ai/threats/cve-2026-40453-apache-camel-rce-via-case-variant-header-injection-in-non-http"},{"cve":"CVE-2026-40860","cvss":9.8,"epss":0.0153,"slug":"cve-2026-40860-apache-camel-remote-code-execution-via-unsafe-jms-deserialization","title":"Apache Camel remote code execution via unsafe JMS deserialization","severity":"critical","exploited":false,"published_at":"2026-04-27T09:16:01.77+00:00","url":"https://junglewise.ai/threats/cve-2026-40860-apache-camel-remote-code-execution-via-unsafe-jms-deserialization"},{"cve":"CVE-2026-43867","cvss":9.8,"epss":0.0093,"slug":"cve-2026-43867-apache-camel-insecure-deserialization-in-pqc-aws-secrets-manager","title":"Apache Camel insecure deserialization in PQC AWS Secrets Manager","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.057+00:00","url":"https://junglewise.ai/threats/cve-2026-43867-apache-camel-insecure-deserialization-in-pqc-aws-secrets-manager"},{"cve":"CVE-2026-46454","cvss":9.8,"epss":0.0083,"slug":"cve-2026-46454-apache-camel-improper-input-validation-in-cometd-component","title":"Apache Camel improper input validation in Cometd component","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.457+00:00","url":"https://junglewise.ai/threats/cve-2026-46454-apache-camel-improper-input-validation-in-cometd-component"},{"cve":"CVE-2026-46456","cvss":9.8,"epss":0.0079,"slug":"cve-2026-46456-apache-camel-aws2-sqs-header-injection-in","title":"Apache Camel AWS2-SQS header injection in Sqs2HeaderFilterStrategy","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.683+00:00","url":"https://junglewise.ai/threats/cve-2026-46456-apache-camel-aws2-sqs-header-injection-in"},{"cve":"CVE-2026-78329","cvss":9.8,"epss":0.0074,"slug":"cve-2026-78329-apache-camel-undertow-header-filter-bypass-in-endpoint-routes","title":"Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, f","severity":"critical","exploited":false,"published_at":"2026-08-24T17:18:20.23+00:00","url":"https://junglewise.ai/threats/cve-2026-78329-apache-camel-undertow-header-filter-bypass-in-endpoint-routes"},{"cve":"CVE-2026-71300","cvss":9.8,"epss":0.0074,"slug":"cve-2026-71300-apache-camel-atmosphere-websocket-header-injection-in-producer","title":"Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 befor","severity":"critical","exploited":false,"published_at":"2026-08-24T17:18:16.997+00:00","url":"https://junglewise.ai/threats/cve-2026-71300-apache-camel-atmosphere-websocket-header-injection-in-producer"},{"cve":"CVE-2026-46455","cvss":9.8,"epss":0.0069,"slug":"cve-2026-46455-apache-camel-insufficient-session-expiration-in-keycloak","title":"Apache Camel insufficient session expiration in Keycloak component","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.573+00:00","url":"https://junglewise.ai/threats/cve-2026-46455-apache-camel-insufficient-session-expiration-in-keycloak"},{"cve":"CVE-2026-33454","cvss":9.4,"epss":0.0103,"slug":"cve-2026-33454-apache-camel-header-injection-in-camel-mail-component","title":"Apache Camel header injection in Camel-Mail component","severity":"critical","exploited":false,"published_at":"2026-04-27T10:16:07.853+00:00","url":"https://junglewise.ai/threats/cve-2026-33454-apache-camel-header-injection-in-camel-mail-component"}],"generated_at":"2026-09-26T14:07:00.158513+00:00"}