Apache Camel Knative 组件中存在不当输入验证及下游组件输出中特殊元素未正确中和(即“注入”)漏洞。 在 camel-knative 中,Knative 消费者会将传入的 CloudEvent 属性映射到 Camel 消息头。在二进制内容模式下,HTTP 头路径通过 过滤 Camel 内部头;但在结构化内容模式(Content-Type 为 )下,CloudEvent 扩展字段直接从 JSON 体中读取,且所有扩展键均被复制到 Exchange 头中,而未应用任何 (涉及 CloudEventPr
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Camel | 3.15.0< 4.14.9 |
affected |
4.15.0< 4.18.4 |
affected | ||
4.19.0< 4.21.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Camel | 3.15.0 ~ 4.14.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75099 | Apache Allura: Unauthenticated REST disclosure | |
| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter s | |
| CVE-2026-71300 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection | |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keys | |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the co | |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local d | |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local d | |
| CVE-2026-59230 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel |
No comments yet