Apache Camel Atmosphere WebSocket 组件中存在不正确的输入验证漏洞。 该漏洞影响以下 Apache Camel 版本: 4.0.0 至 4.14.9 之前的版本 4.15.0 至 4.18.4 之前的版本 4.19.0 至 4.22.0 之前的版本 在 生产者中,消息发送给哪些已连接的 WebSocket 对等体是通过 Exchange 头信息中的特定字段来决定的。这些头信息包括位于 Camel 命名空间之外的字符串值: 、 ,以及 、 和 。由于 继承自 ,因此也继承了 ,而该策略
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Camel | 4.0.0< 4.14.9 |
affected |
4.15.0< 4.18.4 |
affected | ||
4.19.0< 4.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Camel | 4.0.0 ~ 4.14.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75099 | Apache Allura: Unauthenticated REST disclosure | |
| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter s | |
| CVE-2026-63621 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mo | |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keys | |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the co | |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local d | |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local d | |
| CVE-2026-59230 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel |
No comments yet