Known vulnerabilities in Apache Camel
Vendor:
Apache Foundation
Software:
Apache Camel
Software CPE:
cpe:2.3:a:apache_foundation:apache_camel:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
66
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.0.0.0
4.18.4
4.14.9
4.22.0
4.14.8
4.18.3
4.21.0
4.20.0
4.14.7
4.18.2
4.14.6
4.19.0
4.18.1
4.18.0
4.14.5
4.10.9
4.17.0
4.14.4
4.14.3
4.10.8
4.16.0
4.14.2
4.15.0
4.14.1
4.10.7
4.8.9
4.14.0
4.13.0
4.10.6
4.8.8
4.10.5
4.12.0
4.8.7
4.10.4
4.11.0
4.8.6
4.10.3
4.10.2
3.22.4
4.8.5
4.10.1
4.8.4
4.10.0
4.4.5
4.8.3
3.22.3
4.8.2
4.9.0
4.8.1
4.4.4
4.8.0
4.0.6
4.7.0
4.4.3
3.21.5
4.6.0
3.22.2
4.0.5
4.4.2
4.5.0
4.4.1
4.4.0
4.0.4
3.22.1
3.21.4
3.22.0
4.3.0
3.21.3
3.20.9
4.0.3
4.2.0
3.14.10
3.20.8
3.21.2
4.0.2
4.1.0
3.20.7
3.21.1
4.0.1
4.0.0-M1
4.0.0
3.21.0
3.20.6
3.14.9
3.18.8
3.14.8
3.20.5
3.18.7
3.20.4
3.18.6
3.20.3
3.20.2
3.18.5
3.20.1
3.20.0
3.14.7
3.18.4
3.14.6
3.18.3
3.19.0
3.18.2
3.14.5
3.18.1
3.18.0
3.14.4
3.17.0
3.14.3
3.11.7
3.16.0
3.11.6
3.14.2
3.15.0
3.14.1
3.11.5
3.7.7
3.14.0
3.11.4
3.13.0
3.11.3
3.7.6
3.12.0
3.11.2
3.11.1
3.7.5
3.11.0
3.4.6
2.25.4
3.10.0
3.7.4
3.9.0
3.7.3
3.8.0
3.7.2
3.7.1
2.25.3
3.4.5
3.7.0
3.6.0
3.4.4
3.5.0
3.4.3
3.4.2
2.25.2
3.4.1
3.4.0
3.3.0
3.2.0
3.1.0
3.0.1
3.0.0
2.25.1
2.25.0
2.24.3
2.24.2
2.23.4
2.24.1
2.23.3
2.22.5
2.24.0
2.23.2
2.23.1
2.23.0
2.22.4
2.22.3
2.22.2
2.22.1
2.22.0
2.21.5
2.21.4
2.21.3
2.21.2
2.19.5
2.19.4
2.19.3
2.19.2
2.19.1
2.19.0
2.18.5
2.18.4
2.18.3
2.18.2
2.18.1
2.18.0
2.17.7
2.17.6
2.17.5
2.17.4
2.17.3
2.17.2
2.17.1
2.17.0
2.16.4
2.16.3
2.16.2
2.16.1
2.16.0
2.15.6
2.15.5
2.15.4
2.15.3
2.15.2
2.15.1
2.15.0
2.14.4
2.14.3
2.14.2
2.14.1
2.14.0
2.13.4
2.13.3
2.13.2
2.13.1
2.13.0
2.12.5
2.12.4
2.12.3
2.12.2
2.12.1
2.12.0
2.11.4
2.11.3
2.11.2
2.11.1
2.11.0
2.10.7
2.10.6
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.8
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.9.0
2.8.6
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.6.0
2.5.0
2.4.0
2.3.0
2.2.0
2.1.0
2.0.0
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.0
1.4.0
1.3.0
1.2.0
1.1.0
1.0.0
2.21.0
2.20.3
2.20.2
2.20.1
2.20.0
2.21.1
2.20.4
Vulnerabilities (66)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145340 - Deserialization of Untrusted Data CVE-2026-40858 |
CWE-502 | Medium | 4.14.7, 4.18.2, 4.20.0 | 25.08.2026 |
SB20260825109 |
||
| #VU145339 - Deserialization of Untrusted Data CVE-2026-40473 |
CWE-502 | High | 4.14.6, 4.18.2, 4.20.0 | 25.08.2026 |
SB2026082591 |
||
| #VU145338 - Improper input validation CVE-2026-40453 |
CWE-20 | Medium | 4.14.6, 4.18.2, 4.20.0 | 25.08.2026 |
SB2026082591 SB20260825112 |
||
| #VU145336 - Improper Authentication CVE-2026-40022 |
CWE-287 | Medium | 4.14.6, 4.18.2, 4.20.0 | 25.08.2026 |
SB2026082591 |
||
| #VU145335 - Improper input validation CVE-2026-33454 |
CWE-20 | High | 4.14.6, 4.18.1, 4.19.0 | 25.08.2026 |
SB2026082591 SB20260825112 |
||
| #VU145334 - Deserialization of Untrusted Data CVE-2026-27172 |
CWE-502 | Medium | 4.14.6, 4.18.1, 4.19.0 | 25.08.2026 |
SB2026082591 |
||
| #VU145285 - Improper input validation CVE-2026-47323 |
CWE-20 | High | 4.14.6, 4.18.2, 4.19.0 | 25.08.2026 |
SB2026082591 |
||
| #VU145150 - Improper input validation CVE-2026-78329 |
CWE-20 | Medium | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145149 - Improper input validation CVE-2026-71300 |
CWE-20 | Medium | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145148 - Improper Authentication CVE-2026-66908 |
CWE-287 | High | 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145147 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-66907 |
CWE-22 | Low | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145146 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-66906 |
CWE-22 | Low | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145145 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2026-63621 |
CWE-74 | High | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145144 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-60093 |
CWE-22 | Low | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU145143 - Improper input validation CVE-2026-59230 |
CWE-20 | Medium | 4.14.9, 4.18.4, 4.22.0 | 25.08.2026 |
SB2026082548 |
||
| #VU144862 - Improper input validation CVE-2026-56140 |
CWE-20 | Low | 4.2.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, 4.9.0, 4.10.0, 4.11.0, 4.12.0, 4.13.0, 4.14.0, 4.14.8, 4.17.0, 4.18.0, 4.18.3, 4.21.0 | 24.08.2026 |
SB20260824158 |
||
| #VU144705 - Improper input validation CVE-2026-46456 |
CWE-20 | Low | 4.15.0, 4.19.0, 4.21.0 | 24.08.2026 |
SB20260824128 |
||
| #VU144704 - Improper input validation CVE-2026-46457 |
CWE-20 | High | 4.15.0, 4.19.0, 4.21.0 | 24.08.2026 |
SB20260824128 |
||
| #VU144703 - Improper input validation CVE-2026-46584 |
CWE-20 | Medium | 4.15.0, 4.19.0, 4.21.0 | 24.08.2026 |
SB20260824128 |
||
| #VU144702 - Authorization Bypass Through User-Controlled Key CVE-2026-46585 |
CWE-639 | Medium | 4.15.0, 4.19.0, 4.21.0 | 24.08.2026 |
SB20260824128 |
Showing elements 1 - 20 out of 66