HIGHMaven →
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Affected packages
- org.apache.camel:camel-google-storage— 4.0.0 → 4.14.9
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-66907
- https://github.com/apache/camel/pull/25179
- https://github.com/apache/camel/pull/25180
- https://github.com/apache/camel/pull/25181
- https://github.com/apache/camel/pull/25182
- https://github.com/apache/camel/commit/277ab7b7af9bd3beb789d458d54b00b704647191
- https://github.com/apache/camel/commit/4b9b4ade15148e1512b39f302075b36c7a092e86
- https://github.com/apache/camel/commit/a6f73c6d2828fe2b76bf423bad92f98d80af7437
- https://camel.apache.org/security/CVE-2026-66907.html
- https://github.com/apache/camel
- https://github.com/apache/camel/releases/tag/camel-4.14.9
- https://github.com/apache/camel/releases/tag/camel-4.18.4
- https://github.com/apache/camel/releases/tag/camel-4.22.0
- https://issues.apache.org/jira/browse/CAMEL-24279
- http://www.openwall.com/lists/oss-security/2026/08/24/11
Structured record: https://osv.dev/vulnerability/GHSA-f78g-9385-qxqj
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta