Back to blog

// OSSeva Blog

Security

Apache Camel Vulnerabilities by Version: CVEs for Camel 3.x and the 4.x LTS Lines

Randall McClure9 min read

The short answer

Camel's download page lists two supported LTS lines: 4.22, end of life in August 2027, and 4.18, end of life in February 2027. Their latest releases are 4.22.1 from 17 September 2026 and 4.18.4 from 17 August 2026. Camel says an LTS line gets bug and security fixes for up to one year. Every other line is unsupported, including 4.14, whose last release was 4.14.9 on 16 August 2026. Camel 3 reached end of life at the end of 2024, and its final release was 3.22.4 on 9 March 2025. In 2026 alone the project has published ten CVEs against Camel core components whose affected ranges include 3.x versions, and none has a 3.x fix.

Camel release lines and support status

LineStatusLatest release
4.22 LTSSupported, end of life August 20274.22.1, 17 September 2026
4.18 LTSSupported, end of life February 20274.18.4, 17 August 2026
4.14 LTSNo longer listed as supported4.14.9, 16 August 2026
4.10 LTSUnsupported4.10.9, 12 February 2026
4.8 LTSUnsupported4.8.9, 17 September 2025
4.4 LTSUnsupported4.4.5, 22 January 2025
3.xEnd of life at the end of 20243.22.4, 9 March 2025

Camel Spring Boot is released with Camel core and uses the same version number, so it follows the same lifecycle. For every line and date, see the Apache Camel end of life tracker.

Notable Camel CVEs by release line

CVSS is NVD's own score where NVD has scored the record. Most Camel records carry only the CVSS 3.1 score CISA-ADP added, marked CISA-ADP. The Camel project's own rating is often lower, because many of these need a particular route design to be exploitable.

CVEComponent and issueCVSSCamel ratingFixed inCamel 3.x
CVE-2026-33453camel-coap maps request query parameters straight into headers, so routes forwarding to camel-exec can run commands10.0 (CISA-ADP)High4.14.6, 4.18.1, 4.19.0Not affected; starts at 4.14.0
CVE-2026-40453Incomplete fix for CVE-2025-27636 in the JMS, SJMS, CoAP and Google Pub/Sub header filters9.9 (CISA-ADP)Medium4.14.6, 4.18.2, 4.20.0No fix
CVE-2026-40860camel-jms, camel-sjms and camel-amqp deserialize JMS ObjectMessage payloads with no filter9.8 (CISA-ADP)High4.14.7, 4.18.2, 4.20.0No fix
CVE-2026-47323CXF and Knative HTTP endpoints do not filter inbound Camel headers9.8 (CISA-ADP)Medium4.14.6, 4.18.2, 4.19.0No fix; starts at 3.18.0
CVE-2026-53913camel-keycloak accepts any bearer token when no roles or permissions are required9.8 (CISA-ADP)High4.18.3, 4.21.0Not affected; starts at 4.15.0
CVE-2026-33454camel-mail consumers map Camel headers from inbound mail9.4 (CISA-ADP)High4.14.6, 4.18.1, 4.19.0No fix
CVE-2026-27172camel-consul deserializes values from the Consul KV store with no filter8.8 (CISA-ADP)High4.14.6, 4.18.1, 4.19.0No fix
CVE-2026-25747camel-leveldb aggregation repository deserializes stored data with no filter8.8 (NVD)High4.10.9, 4.14.5, 4.18.0No fix
CVE-2026-40473camel-mina ObjectInput converter deserializes network input with no filter8.8 (CISA-ADP)Medium4.14.6, 4.18.2, 4.20.0No fix
CVE-2026-66908platform-http-main JWT authentication skips issuer and audience checks7.5 (CISA-ADP)High4.22.0 onlyNot affected; starts at 4.8.0
CVE-2026-43866JMS deserialization filter from CVE-2026-40860 bypassed with a forged DefaultExchangeHolder7.3 (CISA-ADP)High4.14.8, 4.18.3, 4.21.0No fix
CVE-2026-59230camel-mail MimeMultipart data format copies MIME headers without a filter6.5 (CISA-ADP)Medium4.14.9, 4.18.4, 4.22.0No fix; starts at 2.17.0
CVE-2025-27636Default incoming header filter lets Camel headers through to camel-bean, camel-jms and camel-exec5.6 (CISA-ADP)Medium3.22.4, 4.8.5, 4.10.2Fixed in 3.22.4
CVE-2025-29891The same header injection through HTTP request parameters4.8 (CISA-ADP)High3.22.4, 4.8.5, 4.10.2Fixed in 3.22.4
CVE-2024-23114camel-cassandraql aggregation repository deserializes stored data with no filter9.8 (CISA-ADP)High3.21.4, 3.22.1, 4.0.4, 4.4.0Fixed in 3.21.4 and 3.22.1

Two patterns account for most of this list. The first is header injection. Camel components read control headers, such as the command for camel-exec or the file name for camel-file, from the message, and a consumer that copies external input into headers without a filter lets an outside sender set them. CVE-2025-27636 fixed the default filter, and the 2026 CVEs closed the same gap in mail, JMS, CXF, CoAP, Knative and other consumers one by one. The second is Java deserialization with no ObjectInputFilter in aggregation repositories, registries and message converters.

Camel 4.22 LTS

Camel 4.22 is the newest LTS line, released on 11 August 2026 and supported until August 2027. It supports Java 17, 21 and 25. It is the only line with a fix for CVE-2026-66908: the advisory lists 4.22.0 as the sole fixed version, so 4.18 and older lines that use JWT authentication on the embedded camel-main HTTP server stay exposed.

Camel 4.18 LTS

Camel 4.18 has had four patch releases since 4.18.0 in February 2026, and 4.18.4 carries the fixes for every 4.18 CVE above except CVE-2026-66908. Its end of life is February 2027, about five months away, after which it drops off the download page as 4.14 already has. See Apache Camel 4.18 end of life.

Camel 4.14 and older 4.x LTS lines

Camel 4.14.9, released on 16 August 2026, fixed the August 2026 batch, including CVE-2026-59230. 4.14 no longer appears among the supported releases, so later fixes may not reach it. 4.10 stopped at 4.10.9 in February 2026, before the fixes for CVE-2026-27172, CVE-2026-33454, CVE-2026-40453 and CVE-2026-40860 shipped in March and April 2026. 4.8 and 4.4 stopped earlier still.

Camel 3.x

The Camel team announced that Camel 3 was end of life at the end of 2024, and 3.22.4 on 9 March 2025 was its last release. That release fixed CVE-2025-27636 and CVE-2025-29891. Since then the project has published ten CVEs in 2026 whose ranges include 3.x versions: CVE-2026-25747, CVE-2026-27172, CVE-2026-33454, CVE-2026-40453, CVE-2026-40473, CVE-2026-40860, CVE-2026-43866, CVE-2026-47323, CVE-2026-59230 and CVE-2026-63621. Their fixes exist only on 4.x. Several are the header injection and deserialization bugs above, so a 3.x route that consumes JMS ObjectMessages or mail and forwards to camel-exec, camel-bean or camel-sql is in scope. See Apache Camel 3 end of life and the Camel 3 to 4 migration guide.

What to do on each line

  • 4.22. Stay on the latest patch release.
  • 4.18. Move to 4.18.4 now, and plan the move to 4.22 before February 2027. If you use JWT authentication on platform-http-main, CVE-2026-66908 is a reason to move sooner.
  • 4.14 and older 4.x. Upgrade to 4.18 or 4.22. The step stays within Camel 4 and Jakarta EE, so it is a smaller change than leaving 3.x.
  • 3.x. Migrate to 4.x, which means the javax to jakarta change and Java 17, or take patched builds from a supplier that backports fixes. Until then, filter Camel headers yourself at every consumer that takes external input, and avoid consuming JMS ObjectMessages from untrusted publishers.

Where OSSeva fits

OSSeva backports Camel security fixes to 2.x, 3.x and expired 4.x LTS lines, patching the components you use and the libraries they bundle, and delivers them as Maven, Gradle and Spring Boot starter artifacts. They are available now on the Patch, Assure and Operate tiers. Assure adds a route and component inventory, a Jakarta migration impact assessment and a staged upgrade plan to a supported LTS, and Operate adds 24/7 route monitoring with a 15-minute P1 response and named Camel engineers. See Apache Camel extended support.

Tags

Apache CamelCVECamel 3Camel 4End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.