Known vulnerabilities in Apache Camel

Software: Apache Camel
Software CPE: cpe:2.3:a:apache_foundation:apache_camel:*:*:*:*:*:*:*:*
Total vulnerabilities: 66
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Camel Apache Camel is affected by 66 known vulnerabilities: 18 high, 37 medium, 11 low Critical High Medium Low

Vulnerabilities (66)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145340 - Deserialization of Untrusted Data
CVE-2026-40858
CWE-502 Medium
No
No
4.14.7, 4.18.2, 4.20.0 25.08.2026 SB20260825109
#VU145339 - Deserialization of Untrusted Data
CVE-2026-40473
CWE-502 High
No
No
4.14.6, 4.18.2, 4.20.0 25.08.2026 SB2026082591
#VU145338 - Improper input validation
CVE-2026-40453
CWE-20 Medium
No
No
4.14.6, 4.18.2, 4.20.0 25.08.2026 SB2026082591
SB20260825112
#VU145336 - Improper Authentication
CVE-2026-40022
CWE-287 Medium
No
No
4.14.6, 4.18.2, 4.20.0 25.08.2026 SB2026082591
#VU145335 - Improper input validation
CVE-2026-33454
CWE-20 High
No
No
4.14.6, 4.18.1, 4.19.0 25.08.2026 SB2026082591
SB20260825112
#VU145334 - Deserialization of Untrusted Data
CVE-2026-27172
CWE-502 Medium
No
No
4.14.6, 4.18.1, 4.19.0 25.08.2026 SB2026082591
#VU145285 - Improper input validation
CVE-2026-47323
CWE-20 High
No
No
4.14.6, 4.18.2, 4.19.0 25.08.2026 SB2026082591
#VU145150 - Improper input validation
CVE-2026-78329
CWE-20 Medium
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145149 - Improper input validation
CVE-2026-71300
CWE-20 Medium
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145148 - Improper Authentication
CVE-2026-66908
CWE-287 High
No
No
4.22.0 25.08.2026 SB2026082548
#VU145147 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66907
CWE-22 Low
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145146 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66906
CWE-22 Low
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145145 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-63621
CWE-74 High
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145144 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-60093
CWE-22 Low
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU145143 - Improper input validation
CVE-2026-59230
CWE-20 Medium
No
No
4.14.9, 4.18.4, 4.22.0 25.08.2026 SB2026082548
#VU144862 - Improper input validation
CVE-2026-56140
CWE-20 Low
No
No
4.2.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, 4.9.0, 4.10.0, 4.11.0, 4.12.0, 4.13.0, 4.14.0, 4.14.8, 4.17.0, 4.18.0, 4.18.3, 4.21.0 24.08.2026 SB20260824158
#VU144705 - Improper input validation
CVE-2026-46456
CWE-20 Low
No
No
4.15.0, 4.19.0, 4.21.0 24.08.2026 SB20260824128
#VU144704 - Improper input validation
CVE-2026-46457
CWE-20 High
No
No
4.15.0, 4.19.0, 4.21.0 24.08.2026 SB20260824128
#VU144703 - Improper input validation
CVE-2026-46584
CWE-20 Medium
No
No
4.15.0, 4.19.0, 4.21.0 24.08.2026 SB20260824128
#VU144702 - Authorization Bypass Through User-Controlled Key
CVE-2026-46585
CWE-639 Medium
No
No
4.15.0, 4.19.0, 4.21.0 24.08.2026 SB20260824128


Showing elements 1 - 20 out of 66