Apache Camel Vulnerabilities

6 advisories affecting Apache Camel

6

Total CVEs

4

Critical

2

High

CVE-2026-33453

Apr 27, 2026

Critical (10.0)

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message h...

Read Advisory

CVE-2026-33454

Apr 27, 2026

Critical (9.4)

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOut...

Read Advisory

CVE-2026-40453

Apr 27, 2026

Critical (9.9)

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecu...

Read Advisory

CVE-2026-40860

Apr 27, 2026

Critical (9.8)

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() w...

Read Advisory

CVE-2026-40473

Apr 27, 2026

High (8.8)

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. W...

Read Advisory

CVE-2026-40858

Apr 27, 2026

High (8.8)

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputF...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.