CRITICALMaven →
Apache Camel has an incomplete fix for CVE-2025-27636
Apache Camel has an incomplete fix for CVE-2025-27636
Affected packages
- org.apache.camel:camel-coap— 3.0.0 → 4.14.6
- org.apache.camel:camel-google-pubsub— 3.0.0 → 4.14.6
- org.apache.camel:camel-jms— 3.0.0 → 4.14.6
- org.apache.camel:camel-sjms— 3.0.0 → 4.14.6
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-40453
- https://github.com/apache/camel/pull/22569
- https://github.com/apache/camel/pull/22575
- https://github.com/apache/camel/pull/22576
- https://github.com/apache/camel/commit/1e331daa4eea0a3f01d951e74cda8faee79495a2
- https://github.com/apache/camel/commit/301bb7401cd480895b94a28a8ad6cf04952d8125
- https://github.com/apache/camel/commit/3d2efeed2f6ea757f0254a1d1cdeb9a4f28ca147
- https://camel.apache.org/security/CVE-2026-40453.html
- https://github.com/apache/camel
- https://issues.apache.org/jira/browse/CAMEL-23313
Structured record: https://osv.dev/vulnerability/GHSA-jg2m-9x48-3gvj
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta