VendorsApachecamelall versions
Vulnerabilities

Apache Camel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

86CVEs
CVE-2026-49099
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
Published 2026-07-06 · Analyzed
5.3EPSS 0.005
CVE-2015-0263
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
Published 2015-06-03 · Modified
5.0EPSS 0.075
CVE-2015-0264
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
Published 2015-06-03 · Modified
5.0EPSS 0.070
CVE-2025-29891
Apache Camel: Camel Message Header Injection through request parameters
Published 2025-03-12 · Analyzed
4.8EPSS 0.757
CVE-2026-46584
Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters
Published 2026-07-06 · Analyzed
3.7EPSS 0.006
CVE-2023-34442
Apache Camel JIRA: Temporary file information disclosure in Camel-Jira
Published 2023-07-10 · Modified
3.3EPSS 0.004
← Prev3 / 3