|
2141
|
9.9 |
CRITICAL
Network
|
apache
|
camel
|
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExec…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2026-40453
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2142
|
7.8 |
HIGH
Local
|
apache
|
camel
|
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40048
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2143
|
8.8 |
HIGH
Network
|
apache
|
camel
|
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40473
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2144
|
9.8 |
CRITICAL
Network
|
apache
|
camel
|
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40860
|
2026-04-29 04:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2145
|
9.4 |
CRITICAL
Network
|
apache
|
camel
|
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33454
|
2026-04-29 04:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2146
|
8.2 |
HIGH
Network
|
apache
|
camel
|
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via c…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40022
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2147
|
8.8 |
HIGH
Network
|
apache
|
camel
|
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInput…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40858
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2148
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-me…
|
CWE-863
Incorrect Authorization
|
CVE-2026-41908
|
2026-04-29 04:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2149
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers w…
|
CWE-863
Incorrect Authorization
|
CVE-2026-41909
|
2026-04-29 04:40 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2150
|
10.0 |
CRITICAL
Network
|
apache
|
camel
|
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.
Apache Camel's camel-coap component is vulnerable to Camel message …
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-33453
|
2026-04-29 04:39 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|