// OSSeva Blog
SecurityApache Camel Vulnerabilities by Version: CVEs for Camel 3.x and the 4.x LTS Lines
The short answer
Camel's download page lists two supported LTS lines: 4.22, end of life in August 2027, and 4.18, end of life in February 2027. Their latest releases are 4.22.1 from 17 September 2026 and 4.18.4 from 17 August 2026. Camel says an LTS line gets bug and security fixes for up to one year. Every other line is unsupported, including 4.14, whose last release was 4.14.9 on 16 August 2026. Camel 3 reached end of life at the end of 2024, and its final release was 3.22.4 on 9 March 2025. In 2026 alone the project has published ten CVEs against Camel core components whose affected ranges include 3.x versions, and none has a 3.x fix.
Camel release lines and support status
| Line | Status | Latest release |
|---|---|---|
| 4.22 LTS | Supported, end of life August 2027 | 4.22.1, 17 September 2026 |
| 4.18 LTS | Supported, end of life February 2027 | 4.18.4, 17 August 2026 |
| 4.14 LTS | No longer listed as supported | 4.14.9, 16 August 2026 |
| 4.10 LTS | Unsupported | 4.10.9, 12 February 2026 |
| 4.8 LTS | Unsupported | 4.8.9, 17 September 2025 |
| 4.4 LTS | Unsupported | 4.4.5, 22 January 2025 |
| 3.x | End of life at the end of 2024 | 3.22.4, 9 March 2025 |
Camel Spring Boot is released with Camel core and uses the same version number, so it follows the same lifecycle. For every line and date, see the Apache Camel end of life tracker.
Notable Camel CVEs by release line
CVSS is NVD's own score where NVD has scored the record. Most Camel records carry only the CVSS 3.1 score CISA-ADP added, marked CISA-ADP. The Camel project's own rating is often lower, because many of these need a particular route design to be exploitable.
| CVE | Component and issue | CVSS | Camel rating | Fixed in | Camel 3.x |
|---|---|---|---|---|---|
| CVE-2026-33453 | camel-coap maps request query parameters straight into headers, so routes forwarding to camel-exec can run commands | 10.0 (CISA-ADP) | High | 4.14.6, 4.18.1, 4.19.0 | Not affected; starts at 4.14.0 |
| CVE-2026-40453 | Incomplete fix for CVE-2025-27636 in the JMS, SJMS, CoAP and Google Pub/Sub header filters | 9.9 (CISA-ADP) | Medium | 4.14.6, 4.18.2, 4.20.0 | No fix |
| CVE-2026-40860 | camel-jms, camel-sjms and camel-amqp deserialize JMS ObjectMessage payloads with no filter | 9.8 (CISA-ADP) | High | 4.14.7, 4.18.2, 4.20.0 | No fix |
| CVE-2026-47323 | CXF and Knative HTTP endpoints do not filter inbound Camel headers | 9.8 (CISA-ADP) | Medium | 4.14.6, 4.18.2, 4.19.0 | No fix; starts at 3.18.0 |
| CVE-2026-53913 | camel-keycloak accepts any bearer token when no roles or permissions are required | 9.8 (CISA-ADP) | High | 4.18.3, 4.21.0 | Not affected; starts at 4.15.0 |
| CVE-2026-33454 | camel-mail consumers map Camel headers from inbound mail | 9.4 (CISA-ADP) | High | 4.14.6, 4.18.1, 4.19.0 | No fix |
| CVE-2026-27172 | camel-consul deserializes values from the Consul KV store with no filter | 8.8 (CISA-ADP) | High | 4.14.6, 4.18.1, 4.19.0 | No fix |
| CVE-2026-25747 | camel-leveldb aggregation repository deserializes stored data with no filter | 8.8 (NVD) | High | 4.10.9, 4.14.5, 4.18.0 | No fix |
| CVE-2026-40473 | camel-mina ObjectInput converter deserializes network input with no filter | 8.8 (CISA-ADP) | Medium | 4.14.6, 4.18.2, 4.20.0 | No fix |
| CVE-2026-66908 | platform-http-main JWT authentication skips issuer and audience checks | 7.5 (CISA-ADP) | High | 4.22.0 only | Not affected; starts at 4.8.0 |
| CVE-2026-43866 | JMS deserialization filter from CVE-2026-40860 bypassed with a forged DefaultExchangeHolder | 7.3 (CISA-ADP) | High | 4.14.8, 4.18.3, 4.21.0 | No fix |
| CVE-2026-59230 | camel-mail MimeMultipart data format copies MIME headers without a filter | 6.5 (CISA-ADP) | Medium | 4.14.9, 4.18.4, 4.22.0 | No fix; starts at 2.17.0 |
| CVE-2025-27636 | Default incoming header filter lets Camel headers through to camel-bean, camel-jms and camel-exec | 5.6 (CISA-ADP) | Medium | 3.22.4, 4.8.5, 4.10.2 | Fixed in 3.22.4 |
| CVE-2025-29891 | The same header injection through HTTP request parameters | 4.8 (CISA-ADP) | High | 3.22.4, 4.8.5, 4.10.2 | Fixed in 3.22.4 |
| CVE-2024-23114 | camel-cassandraql aggregation repository deserializes stored data with no filter | 9.8 (CISA-ADP) | High | 3.21.4, 3.22.1, 4.0.4, 4.4.0 | Fixed in 3.21.4 and 3.22.1 |
Two patterns account for most of this list. The first is header injection. Camel components read control headers, such as the command for camel-exec or the file name for camel-file, from the message, and a consumer that copies external input into headers without a filter lets an outside sender set them. CVE-2025-27636 fixed the default filter, and the 2026 CVEs closed the same gap in mail, JMS, CXF, CoAP, Knative and other consumers one by one. The second is Java deserialization with no ObjectInputFilter in aggregation repositories, registries and message converters.
Camel 4.22 LTS
Camel 4.22 is the newest LTS line, released on 11 August 2026 and supported until August 2027. It supports Java 17, 21 and 25. It is the only line with a fix for CVE-2026-66908: the advisory lists 4.22.0 as the sole fixed version, so 4.18 and older lines that use JWT authentication on the embedded camel-main HTTP server stay exposed.
Camel 4.18 LTS
Camel 4.18 has had four patch releases since 4.18.0 in February 2026, and 4.18.4 carries the fixes for every 4.18 CVE above except CVE-2026-66908. Its end of life is February 2027, about five months away, after which it drops off the download page as 4.14 already has. See Apache Camel 4.18 end of life.
Camel 4.14 and older 4.x LTS lines
Camel 4.14.9, released on 16 August 2026, fixed the August 2026 batch, including CVE-2026-59230. 4.14 no longer appears among the supported releases, so later fixes may not reach it. 4.10 stopped at 4.10.9 in February 2026, before the fixes for CVE-2026-27172, CVE-2026-33454, CVE-2026-40453 and CVE-2026-40860 shipped in March and April 2026. 4.8 and 4.4 stopped earlier still.
Camel 3.x
The Camel team announced that Camel 3 was end of life at the end of 2024, and 3.22.4 on 9 March 2025 was its last release. That release fixed CVE-2025-27636 and CVE-2025-29891. Since then the project has published ten CVEs in 2026 whose ranges include 3.x versions: CVE-2026-25747, CVE-2026-27172, CVE-2026-33454, CVE-2026-40453, CVE-2026-40473, CVE-2026-40860, CVE-2026-43866, CVE-2026-47323, CVE-2026-59230 and CVE-2026-63621. Their fixes exist only on 4.x. Several are the header injection and deserialization bugs above, so a 3.x route that consumes JMS ObjectMessages or mail and forwards to camel-exec, camel-bean or camel-sql is in scope. See Apache Camel 3 end of life and the Camel 3 to 4 migration guide.
What to do on each line
- 4.22. Stay on the latest patch release.
- 4.18. Move to 4.18.4 now, and plan the move to 4.22 before February 2027. If you use JWT authentication on platform-http-main, CVE-2026-66908 is a reason to move sooner.
- 4.14 and older 4.x. Upgrade to 4.18 or 4.22. The step stays within Camel 4 and Jakarta EE, so it is a smaller change than leaving 3.x.
- 3.x. Migrate to 4.x, which means the javax to jakarta change and Java 17, or take patched builds from a supplier that backports fixes. Until then, filter Camel headers yourself at every consumer that takes external input, and avoid consuming JMS ObjectMessages from untrusted publishers.
Where OSSeva fits
OSSeva backports Camel security fixes to 2.x, 3.x and expired 4.x LTS lines, patching the components you use and the libraries they bundle, and delivers them as Maven, Gradle and Spring Boot starter artifacts. They are available now on the Patch, Assure and Operate tiers. Assure adds a route and component inventory, a Jakarta migration impact assessment and a staged upgrade plan to a supported LTS, and Operate adds 24/7 route monitoring with a 15-minute P1 response and named Camel engineers. See Apache Camel extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.