These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-64609 is a critical vulnerability in Apache Fory, a software project formerly known as Apache Fury. The issue allows for an out-of-bounds read via sun.misc.Unsafe, specifically when using out-of-band zero-copy deserialization. This feature is opt-in, meaning applications not using it are not affected. The vulnerability impacts Apache Fory versions from 0.5.0 up to but not including 1.4.0. Users a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T10:16:24.923Z and has not been modified since then. The vulnerability is a heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual [truncated]
The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured 'buildRoot' directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains '../' sequenc [truncated]
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. This allows a user with write access to the source GCS bucket to create an object whose name contains `..` segments and cause the DAG run to write the downloaded [truncated]
CVE-2026-49042 is an Improper Input Validation vulnerability in Apache Camel. The issue affects Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3 or 4.21.0, which fixes the issue. This vulnerability has a CVSS score of 7.3 and a severity of HIGH. The affected product deployments should be reviewed for potential exposure.
CVE-2026-46588 is an Improper Input Validation vulnerability affecting Apache Camel versions through 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0. This issue can lead to potential security risks if not addressed. Users are advised to upgrade to version 4.14.8, 4.18.3, or 4.21.0 to fix the issue. The CVSS score for this vulnerability is 7.3, indicating a high severity. It is essential [truncated]
CVE-2026-46587 is an Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0. The vulnerability can be exploited via network, with low attack complexity, no privileges required, and no user interaction needed. The CVSS score for this v [truncated]
The CVE record was published on 2026-07-06T09:16:39.280Z and has not been modified since then. The NVD entry is currently Analyzed. This defense-in-depth hardening change affects Apache Camel from version 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The camel-aws2-sns component has a defense-in-depth update to align with sibling strategies by adding an inbound filter rule [truncated]
The Apache Camel Undertow Component is vulnerable to Generation of Error Message Containing Sensitive Information. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability arises from the camel-undertow HTTP server consumer's exposure of a muteException option that controls what is returned to the client when a route pro [truncated]
The CVE record for CVE-2026-55994 was published on 2026-07-06T09:16:39.033Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel's Iggy component allows an actor able to publish to the consumed Iggy stream/topic to set Camel-inte [truncated]
The Apache Camel IRC component has an Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) vulnerability. This issue allows an attacker to redirect messages intended for a configured IRC channel to an arbitrary channel or user, potentially exfiltrating message content or delivering messages that appear to come from the bot. The vuln [truncated]
CVE-2026-49086 is an Improper Input Validation, Unintended Proxy or Intermediary vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer copied two fields from each inbound CloudEvent into the CamelDaprPubSubName and CamelDaprTopic Exchange headers. These headers are producer-direction routing headers. An actor able to publish a message to the subscribed topic could set the Clou [truncated]
CVE-2026-48206 is an Improper Input Validation and Authorization Bypass Through User-Controlled Key vulnerability in the Apache Camel JIRA component. The vulnerability allows an attacker to override intended JIRA operations by supplying specific headers in an HTTP request, which can lead to unauthorized actions such as deleting or transitioning issues, creating issues in different projects, modifying issu [truncated]
The Apache Camel DNS component has a vulnerability that allows for Server-Side Request Forgery (SSRF) attacks due to improper input validation. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability allows an attacker to make the dig producer build a SimpleResolver pointing at an attacker-controlled DNS server, allowin [truncated]
CVE-2026-48204 is a critical vulnerability in Apache Camel's Camel Mongodb Gridfs component. The vulnerability allows an attacker to perform unintended GridFS operations, including file deletion, enumeration, and reading, by manipulating the gridfs.operation header in an HTTP request. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0.
The CVE record describes a vulnerability in Apache Camel's Vertx Websocket component, allowing an attacker to perform a Server-Side Request Forgery (SSRF) attack and gain access to sensitive information. The issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. Users of Apache Camel, particularly those using the Vertx Websocket component, s [truncated]
A vulnerability was found in Apache Camel, specifically in the CXF SOAP component. This issue is related to improper input validation and the unintended use of a proxy or intermediary, often referred to as a 'confused deputy' problem. The vulnerability allows an attacker to manipulate the SOAP operation invoked on a backend service by setting the operationName header in an HTTP request. This can lead to u [truncated]
The CVE record describes a vulnerability in Apache Camel's Neo4J component, where an attacker can inject arbitrary Cypher queries by manipulating the CamelNeo4jMatchProperties map. This issue affects Apache Camel versions from 4.10.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability has a high CVSS score of 8.2 and is considered a high-severity issue. Users of Apac [truncated]
CVE-2026-46590 is a Deserialization of Untrusted Data vulnerability in the Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a Base64-wrapped value with a raw java.i [truncated]
The CVE record describes a vulnerability in Apache Camel's Lucene component, allowing for improper input validation and authorization bypass. An attacker could exploit this by setting the QUERY header in an HTTP request, leading to potential unauthorized access to documents in the full-text index. This vulnerability affects Apache Camel versions 4.0.0 to 4.14.8, 4.15.0 to 4.18.3, and 4.19.0 to 4.21.0. Use [truncated]
The Apache Camel Mail Component is vulnerable to Improper Input Validation and Exposure of Sensitive Information to an Unauthorized Actor. The camel-mail producer scans the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and builds a per-message JavaMail sender with those values applied as JavaMail session properties, overriding the endpoint configuration.
The CVE record describes an Improper Input Validation vulnerability in the Apache Camel NATS component. The issue arises from the camel-nats component mapping inbound NATS message headers into the Camel Exchange without proper filtering, allowing for the injection of arbitrary Camel control headers. This can influence the behavior of downstream producers in the route. The vulnerability affects Apache Came [truncated]
The CVE record was published on 2026-07-06T09:16:36.683Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component allows an attacker to influence the behavior of downstream producers in the route by setting arbitrary Camel control headers. Affected users should be aware of the critical severity of this vulner [truncated]
The CVE record describes an Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. This results in the helper verifying the token signature, subject and issuer but not enforc [truncated]
The CVE record was published on 2026-07-06T09:16:36.317Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation and Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client allows an untrusted HTTP client to set Exchange headers directly and override the query and operation configured by the route author. Th [truncated]
CVE-2026-43867 is a Deserialization of Untrusted Data vulnerability in the Apache Camel PQC Component. The vulnerability exists in the camel-pqc component, which stores post-quantum key metadata through pluggable KeyLifecycleManager implementations. Specifically, AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads metadata from the AWS Secrets Manager secret by Base64-decoding and deserializi [truncated]
CVE-2026-43866 is a Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. The vulnerability exists in the JmsBinding.extractBodyFromJms() method in camel-jms and camel-sjms, which deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() when the mapJmsMessage option is enabled. An attacker can inject arbitrary Exchange state [truncated]
Apache Camel Hazelcast component has a Deserialization of Untrusted Data vulnerability. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. This allows an attacker who can join or reach the Hazelcast cluster to publish a crafted serialized Java object that is then deserialized on every Camel node, resulting in rem [truncated]
The CVE record for CVE-2026-42527 was published on 2026-07-06T09:16:35.657Z and has not been modified since then. The NVD entry is currently Analyzed. This Deserialization of Untrusted Data vulnerability in Apache Camel, specifically in the default ObjectInputFilter pattern used by several components, allows classes whose hashCode/equals/readObject methods perform network I/O, such as java.net.URL and jav [truncated]
CVE-2026-40859 is a Deserialization of Untrusted Data vulnerability in Apache Camel. The vulnerability allows for remote code execution if a suitable gadget chain is present on the classpath. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.20.0. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type [truncated]