PatchSiren

Apache CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Apache CVE published 2026-07-21

CVE-2026-64609

CVE-2026-64609 is a critical vulnerability in Apache Fory, a software project formerly known as Apache Fury. The issue allows for an out-of-bounds read via sun.misc.Unsafe, specifically when using out-of-band zero-copy deserialization. This feature is opt-in, meaning applications not using it are not affected. The vulnerability impacts Apache Fory versions from 0.5.0 up to but not including 1.4.0. Users a [truncated]

CRITICAL Apache CVE published 2026-07-21

CVE-2026-64608

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T10:16:24.923Z and has not been modified since then. The vulnerability is a heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual [truncated]

MEDIUM Apache CVE published 2026-07-15

CVE-2026-26032

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured 'buildRoot' directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains '../' sequenc [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. This allows a user with write access to the source GCS bucket to create an object whose name contains `..` segments and cause the DAG run to write the downloaded [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-49042

CVE-2026-49042 is an Improper Input Validation vulnerability in Apache Camel. The issue affects Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3 or 4.21.0, which fixes the issue. This vulnerability has a CVSS score of 7.3 and a severity of HIGH. The affected product deployments should be reviewed for potential exposure.

HIGH Apache CVE published 2026-07-06

CVE-2026-46588

CVE-2026-46588 is an Improper Input Validation vulnerability affecting Apache Camel versions through 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0. This issue can lead to potential security risks if not addressed. Users are advised to upgrade to version 4.14.8, 4.18.3, or 4.21.0 to fix the issue. The CVSS score for this vulnerability is 7.3, indicating a high severity. It is essential [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46587

CVE-2026-46587 is an Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0. The vulnerability can be exploited via network, with low attack complexity, no privileges required, and no user interaction needed. The CVSS score for this v [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-56140

The CVE record was published on 2026-07-06T09:16:39.280Z and has not been modified since then. The NVD entry is currently Analyzed. This defense-in-depth hardening change affects Apache Camel from version 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The camel-aws2-sns component has a defense-in-depth update to align with sibling strategies by adding an inbound filter rule [truncated]

MEDIUM Apache CVE published 2026-07-06

CVE-2026-56139

The Apache Camel Undertow Component is vulnerable to Generation of Error Message Containing Sensitive Information. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability arises from the camel-undertow HTTP server consumer's exposure of a muteException option that controls what is returned to the client when a route pro [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-55994

The CVE record for CVE-2026-55994 was published on 2026-07-06T09:16:39.033Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel's Iggy component allows an actor able to publish to the consumed Iggy stream/topic to set Camel-inte [truncated]

MEDIUM Apache CVE published 2026-07-06

CVE-2026-49097

The Apache Camel IRC component has an Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) vulnerability. This issue allows an attacker to redirect messages intended for a configured IRC channel to an arbitrary channel or user, potentially exfiltrating message content or delivering messages that appear to come from the bot. The vuln [truncated]

MEDIUM Apache CVE published 2026-07-06

CVE-2026-49086

CVE-2026-49086 is an Improper Input Validation, Unintended Proxy or Intermediary vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer copied two fields from each inbound CloudEvent into the CamelDaprPubSubName and CamelDaprTopic Exchange headers. These headers are producer-direction routing headers. An actor able to publish a message to the subscribed topic could set the Clou [truncated]

MEDIUM Apache CVE published 2026-07-06

CVE-2026-48206

CVE-2026-48206 is an Improper Input Validation and Authorization Bypass Through User-Controlled Key vulnerability in the Apache Camel JIRA component. The vulnerability allows an attacker to override intended JIRA operations by supplying specific headers in an HTTP request, which can lead to unauthorized actions such as deleting or transitioning issues, creating issues in different projects, modifying issu [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-48205

The Apache Camel DNS component has a vulnerability that allows for Server-Side Request Forgery (SSRF) attacks due to improper input validation. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability allows an attacker to make the dig producer build a SimpleResolver pointing at an attacker-controlled DNS server, allowin [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-48204

CVE-2026-48204 is a critical vulnerability in Apache Camel's Camel Mongodb Gridfs component. The vulnerability allows an attacker to perform unintended GridFS operations, including file deletion, enumeration, and reading, by manipulating the gridfs.operation header in an HTTP request. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0.

HIGH Apache CVE published 2026-07-06

CVE-2026-46726

The CVE record describes a vulnerability in Apache Camel's Vertx Websocket component, allowing an attacker to perform a Server-Side Request Forgery (SSRF) attack and gain access to sensitive information. The issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. Users of Apache Camel, particularly those using the Vertx Websocket component, s [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46592

A vulnerability was found in Apache Camel, specifically in the CXF SOAP component. This issue is related to improper input validation and the unintended use of a proxy or intermediary, often referred to as a 'confused deputy' problem. The vulnerability allows an attacker to manipulate the SOAP operation invoked on a backend service by setting the operationName header in an HTTP request. This can lead to u [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46591

The CVE record describes a vulnerability in Apache Camel's Neo4J component, where an attacker can inject arbitrary Cypher queries by manipulating the CamelNeo4jMatchProperties map. This issue affects Apache Camel versions from 4.10.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability has a high CVSS score of 8.2 and is considered a high-severity issue. Users of Apac [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46590

CVE-2026-46590 is a Deserialization of Untrusted Data vulnerability in the Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a Base64-wrapped value with a raw java.i [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46585

The CVE record describes a vulnerability in Apache Camel's Lucene component, allowing for improper input validation and authorization bypass. An attacker could exploit this by setting the QUERY header in an HTTP request, leading to potential unauthorized access to documents in the full-text index. This vulnerability affects Apache Camel versions 4.0.0 to 4.14.8, 4.15.0 to 4.18.3, and 4.19.0 to 4.21.0. Use [truncated]

LOW Apache CVE published 2026-07-06

CVE-2026-46584

The Apache Camel Mail Component is vulnerable to Improper Input Validation and Exposure of Sensitive Information to an Unauthorized Actor. The camel-mail producer scans the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and builds a per-message JavaMail sender with those values applied as JavaMail session properties, overriding the endpoint configuration.

HIGH Apache CVE published 2026-07-06

CVE-2026-46457

The CVE record describes an Improper Input Validation vulnerability in the Apache Camel NATS component. The issue arises from the camel-nats component mapping inbound NATS message headers into the Camel Exchange without proper filtering, allowing for the injection of arbitrary Camel control headers. This can influence the behavior of downstream producers in the route. The vulnerability affects Apache Came [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-46456

The CVE record was published on 2026-07-06T09:16:36.683Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component allows an attacker to influence the behavior of downstream producers in the route by setting arbitrary Camel control headers. Affected users should be aware of the critical severity of this vulner [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-46455

The CVE record describes an Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. This results in the helper verifying the token signature, subject and issuer but not enforc [truncated]

MEDIUM Apache CVE published 2026-07-06

CVE-2026-46453

The CVE record was published on 2026-07-06T09:16:36.317Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Input Validation and Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client allows an untrusted HTTP client to set Exchange headers directly and override the query and operation configured by the route author. Th [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-43867

CVE-2026-43867 is a Deserialization of Untrusted Data vulnerability in the Apache Camel PQC Component. The vulnerability exists in the camel-pqc component, which stores post-quantum key metadata through pluggable KeyLifecycleManager implementations. Specifically, AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads metadata from the AWS Secrets Manager secret by Base64-decoding and deserializi [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-43866

CVE-2026-43866 is a Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. The vulnerability exists in the JmsBinding.extractBodyFromJms() method in camel-jms and camel-sjms, which deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() when the mapJmsMessage option is enabled. An attacker can inject arbitrary Exchange state [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-43865

Apache Camel Hazelcast component has a Deserialization of Untrusted Data vulnerability. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. This allows an attacker who can join or reach the Hazelcast cluster to publish a crafted serialized Java object that is then deserialized on every Camel node, resulting in rem [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-42527

The CVE record for CVE-2026-42527 was published on 2026-07-06T09:16:35.657Z and has not been modified since then. The NVD entry is currently Analyzed. This Deserialization of Untrusted Data vulnerability in Apache Camel, specifically in the default ObjectInputFilter pattern used by several components, allows classes whose hashCode/equals/readObject methods perform network I/O, such as java.net.URL and jav [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-40859

CVE-2026-40859 is a Deserialization of Untrusted Data vulnerability in Apache Camel. The vulnerability allows for remote code execution if a suitable gadget chain is present on the classpath. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.20.0. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type [truncated]