Camel
Vendor:
First CVE: Oct 4, 2013 · Active for 12 years
75
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Camel over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2013
12 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
CVE Severity & Scoring
Camel75 CVEs
21%
43%
33%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (4.0%)
Network67 (89.3%)
Unknown5 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (82.7%)
High8 (10.7%)
Unknown5 (6.7%)
User Interaction
None68 (90.7%)
Unknown5 (6.7%)
Required2 (2.7%)
Privileges Required
Low8 (10.7%)
High0 (0.0%)
None62 (82.7%)
Unknown5 (6.7%)
Top CVEs
Signals from CVEs in this product scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27636MEDIUM Bypass/Injection vulnerability in Apache Camel components under particular conditions.
This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, | Mar 9, 2025 | 5.6 | 69 | NO | NO |
CVE-2025-29891MEDIUM Bypass/Injection vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4.
Users are recommen | Mar 12, 2025 | 4.8 | 60 | NO | NO |
CVE-2026-33453CRITICAL Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.
Apache Camel's camel-coap component is vulnerabl | Apr 27, 2026 | 10.0 | 57 | NO | YES |
CVE-2026-56140CRITICAL Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, S | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-53913CRITICAL Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.
The KeycloakSecurity | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-43867CRITICAL Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecy | Jul 6, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-48204CRITICAL Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs producer selects the GridFS operation | Jul 6, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-46456CRITICAL Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a componen | Jul 6, 2026 | 9.8 | 42 | NO | NO |
CVE-2014-0002HIGH The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML docu | Mar 21, 2014 | 7.5 | 42 | NO | NO |
CVE-2026-46455CRITICAL Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keyc | Jul 6, 2026 | 9.8 | 41 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (75 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (75 CVEs).
Media Mentions
Signals from CVEs in this product scope (75 CVEs).
Top CNAs Publishing CVEs For Camel
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.20.0 | 1 | 8.1 | 0.5% | 0 | 0 |
| 4.19.0 | 7 | 9.0 | 1.5% | 0 | 1 |
| 4.18.0 | 1 | 10.0 | 6.2% | 0 | 1 |
| 4.0.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 3.22.0 | 3 | 8.4 | 0.9% | 0 | 0 |
| 2.9.8 | 1 | 8.1 | 6.4% | 0 | 0 |
| 2.9.7 | 1 | 8.1 | 6.4% | 0 | 0 |
| 2.9.6 | 1 | 8.1 | 6.4% | 0 | 0 |
| 2.9.5 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.9.4 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.9.3 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.9.2 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.9.1 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.9.0 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.6 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.5 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.4 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.3 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.2 | 2 | 7.5 | 7.4% | 0 | 0 |
| 2.8.1 | 2 | 7.5 | 7.4% | 0 | 0 |