VendorsApachecamel4.19.0
Vulnerabilities

Apache Camel 4.19.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-33453
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
Published 2026-04-27 · Modified
10.0EPSS 0.072
CVE-2026-40453
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
Published 2026-04-27 · Modified
9.9EPSS 0.019
CVE-2026-40860
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
Published 2026-04-27 · Modified
9.8EPSS 0.015
CVE-2026-40858
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
Published 2026-04-27 · Modified
8.8EPSS 0.012
CVE-2026-40473
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
Published 2026-04-27 · Modified
8.8EPSS 0.011
CVE-2026-40859
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
Published 2026-07-06 · Analyzed
8.1EPSS 0.009
CVE-2026-40048
Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
Published 2026-04-27 · Modified
7.8EPSS 0.005