← Back

Camel

camel

Vendor: Apache • 75 CVEs

CVEs (75)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Camel
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
1Apache
1Camel
Jun 17, 2026
Sep 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
1Apache
1Camel
Jun 17, 2026
Jul 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
1Apache
1Camel
May 13, 2026
Nov 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 13, 2026
Nov 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 13, 2026
Mar 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
1Apache
1Camel
May 13, 2026
Mar 16, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
1Apache
1Camel
May 13, 2026
Mar 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
1Apache
1Camel
May 6, 2026
Apr 15, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a...Show more
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.Show less
1Apache
1Camel
May 6, 2026
Feb 3, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
1Apache
1Camel
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an inval...Show more
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.Show less
1Apache
1Camel
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an externa...Show more
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.Show less
1Apache
1Camel
May 6, 2026
Mar 21, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
1Apache
1Camel
May 6, 2026
Mar 21, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity decla...Show more
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Apache
1Camel
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (...Show more
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.Show less