← Back

Camel

camel

Vendor: Apache • 83 CVEs

CVEs (83)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Camel
Jun 17, 2026
Feb 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users...Show more
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1 Show less
1Apache
1Camel
Jun 17, 2026
Jul 10, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X th...Show more
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3. Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1 Show less
2Apache
Oracle
4Camel
Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 more
Jun 17, 2026
Jul 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
2Apache
Oracle
4Camel
Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 more
Jun 17, 2026
May 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
2Apache
Oracle
4Camel
Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 more
Jun 17, 2026
May 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
2Apache
Oracle
5Camel
Communications Diameter Intelligence HubCommunications Diameter Signaling Router+2 more
Jun 17, 2026
May 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
4Apache
CanonicalDebian+1 more
4Camel
Debian LinuxHtmlunit+1 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.Show less
2Apache
Oracle
5Camel
Enterprise Data QualityEnterprise Manager Base Platform+2 more
Jun 17, 2026
May 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
1Apache
1Camel
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
1Apache
1Camel
Jun 17, 2026
Sep 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
1Apache
1Camel
Jun 17, 2026
Jul 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
1Apache
1Camel
May 13, 2026
Nov 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 13, 2026
Nov 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 13, 2026
Mar 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
1Apache
1Camel
May 13, 2026
Mar 16, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
1Apache
1Camel
May 13, 2026
Mar 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 6, 2026
Apr 15, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a...Show more
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.Show less
1Apache
1Camel
May 6, 2026
Feb 3, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
1Apache
1Camel
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an inval...Show more
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.Show less
1Apache
1Camel
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an externa...Show more
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.Show less