Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

88 advisories

Loading
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP headers Critical
CVE-2026-48204 was published for org.apache.camel:camel-mongodb-gridfs (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Critical
CVE-2026-40047 was published for org.apache.camel:camel-docling (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution High
CVE-2026-43865 was published for org.apache.camel:camel-hazelcast (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel JMS deserialization filter bypass High
CVE-2026-43866 was published for org.apache.camel:camel-activemq (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure High
CVE-2026-42527 was published for org.apache.camel:camel-amqp (Maven) Jul 6, 2026
oscerd Credited to oscerd
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization High
CVE-2026-41731 was published for org.springframework.kafka:spring-kafka (Maven) Jun 10, 2026
oscerd Credited to oscerd
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage Critical
CVE-2026-40860 was published for org.apache.camel:camel-activemq (Maven) Apr 27, 2026
oscerd Credited to oscerd
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class Moderate
CVE-2026-40180 was published for io.quarkiverse.openapi.generator:quarkus-openapi-generator (Maven) Apr 8, 2026
oscerd Credited to oscerd and ricardozanini ricardozanini ricardozanini
ProTip! Advisories are also available from the GraphQL API