CRITICALMaven

Apache Camel has an incomplete fix for CVE-2025-27636

Apache Camel has an incomplete fix for CVE-2025-27636

CVE-2026-40453Published 4 months agoUpdated 5 days agoSource: OSV

Affected packages

  • org.apache.camel:camel-coap3.0.0 → 4.14.6
  • org.apache.camel:camel-google-pubsub3.0.0 → 4.14.6
  • org.apache.camel:camel-jms3.0.0 → 4.14.6
  • org.apache.camel:camel-sjms3.0.0 → 4.14.6

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Apache Camel has an incomplete fix for CVE-2025-27636 | HackTribune