GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
88 advisories
Filter by severity
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open Vulnerabilities
Critical
CVE-2026-53913
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55994
was published
for
org.apache.camel:camel-iggy
(Maven)
Jul 6, 2026
Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
High
CVE-2026-46590
was published
for
org.apache.camel:camel-pqc
(Maven)
Jul 6, 2026
Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
High
CVE-2026-46591
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jul 6, 2026
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Critical
CVE-2026-48203
was published
for
org.apache.camel:camel-solr
(Maven)
Jul 6, 2026
Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
Critical
CVE-2026-46456
was published
for
org.apache.camel:camel-aws2-sqs
(Maven)
Jul 6, 2026
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-46726
was published
for
org.apache.camel:camel-vertx-websocket
(Maven)
Jul 6, 2026
Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
High
CVE-2026-46585
was published
for
org.apache.camel:camel-lucene
(Maven)
Jul 6, 2026
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered gridfs.* HTTP headers
Critical
CVE-2026-48204
was published
for
org.apache.camel:camel-mongodb-gridfs
(Maven)
Jul 6, 2026
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
Low
CVE-2026-46584
was published
for
org.apache.camel:camel-mail
(Maven)
Jul 6, 2026
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
High
CVE-2026-46592
was published
for
org.apache.camel:camel-cxf-rest
(Maven)
Jul 6, 2026
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
Critical
CVE-2026-40047
was published
for
org.apache.camel:camel-docling
(Maven)
Jul 6, 2026
Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
Moderate
CVE-2026-46453
was published
for
org.apache.camel:camel-elasticsearch-rest-client
(Maven)
Jul 6, 2026
Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
High
CVE-2026-46457
was published
for
org.apache.camel:camel-nats
(Maven)
Jul 6, 2026
Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
Critical
CVE-2026-46455
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
Critical
CVE-2026-46454
was published
for
org.apache.camel:camel-cometd
(Maven)
Jul 6, 2026
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
High
CVE-2026-43865
was published
for
org.apache.camel:camel-hazelcast
(Maven)
Jul 6, 2026
Apache Camel JMS deserialization filter bypass
High
CVE-2026-43866
was published
for
org.apache.camel:camel-activemq
(Maven)
Jul 6, 2026
Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
Critical
CVE-2026-43867
was published
for
org.apache.camel:camel-pqc
(Maven)
Jul 6, 2026
Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
High
CVE-2026-40859
was published
for
org.apache.camel:camel-netty-http
(Maven)
Jul 6, 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
High
CVE-2026-42527
was published
for
org.apache.camel:camel-amqp
(Maven)
Jul 6, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage
Critical
CVE-2026-40860
was published
for
org.apache.camel:camel-activemq
(Maven)
Apr 27, 2026
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
Moderate
CVE-2026-40180
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API