Camel

Vendor:

First CVE: Oct 4, 2013 · Active for 12 years

75
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Camel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2013
12 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

CVE Severity & Scoring

Camel75 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (4.0%)
Network67 (89.3%)
Unknown5 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (82.7%)
High8 (10.7%)
Unknown5 (6.7%)
User Interaction
None68 (90.7%)
Unknown5 (6.7%)
Required2 (2.7%)
Privileges Required
Low8 (10.7%)
High0 (0.0%)
None62 (82.7%)
Unknown5 (6.7%)

Top CVEs

Signals from CVEs in this product scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4,
Mar 9, 20255.669NONO
Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommen
Mar 12, 20254.860NONO
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerabl
Apr 27, 202610.057NOYES
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, S
Jul 6, 20269.843NONO
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurity
Jul 6, 20269.843NONO
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecy
Jul 6, 20269.842NONO
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation
Jul 6, 20269.842NONO
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a componen
Jul 6, 20269.842NONO
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML docu
Mar 21, 20147.542NONO
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keyc
Jul 6, 20269.841NONO

Exploit Exposure

Signals from CVEs in this product scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (75 CVEs).

Media Mentions

Signals from CVEs in this product scope (75 CVEs).

Top CNAs Publishing CVEs For Camel

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.20.018.10.5%00
4.19.079.01.5%01
4.18.0110.06.2%01
4.0.013.30.4%00
3.22.038.40.9%00
2.9.818.16.4%00
2.9.718.16.4%00
2.9.618.16.4%00
2.9.527.57.4%00
2.9.427.57.4%00
2.9.327.57.4%00
2.9.227.57.4%00
2.9.127.57.4%00
2.9.027.57.4%00
2.8.627.57.4%00
2.8.527.57.4%00
2.8.427.57.4%00
2.8.327.57.4%00
2.8.227.57.4%00
2.8.127.57.4%00