Red Hat Build of Apache Camel
38 known vulnerabilities in Red Hat Build of Apache Camel, 4 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-94449 CVSS 7.5 high A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers…
- CVE-2026-93574 CVSS 6.5 medium A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially…
- CVE-2026-93562 CVSS 6.5 medium A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to…
- CVE-2026-93432 CVSS 6.1 medium A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the…
- CVE-2026-93579 CVSS 6.5 medium A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line…
- CVE-2026-93573 CVSS 6.5 medium A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation…
- CVE-2026-93569 CVSS 8.2 high A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process…
- CVE-2026-93568 CVSS 7.5 high A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended…
- CVE-2026-93567 CVSS 7.5 high A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host…
- CVE-2026-93566 CVSS 6.5 medium A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control…
- CVE-2026-93565 CVSS 7.5 high A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens…
- CVE-2026-93564 CVSS 7.5 high A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to…
- CVE-2026-93558 CVSS 7.5 high A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using…
- CVE-2026-10832 CVSS 5.9 medium A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability…
- CVE-2026-93492 CVSS 5.3 medium A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large…
- CVE-2026-93491 CVSS 7.5 high A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1…
- CVE-2026-93488 CVSS 7.5 high A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because…
- CVE-2026-87743 CVSS 7.5 high A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the…
- CVE-2026-89059 CVSS 7.5 high A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the…
- CVE-2026-89058 CVSS 7.4 high A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in…
- CVE-2026-81320 CVSS 5.5 medium A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher…
- CVE-2026-81303 CVSS 6.3 medium A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied…
- CVE-2026-78234 CVSS 9.9 critical A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca…
- CVE-2026-77968 CVSS 8.2 high A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces…
- CVE-2026-86404 CVSS 8.8 high EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses…
- CVE-2026-84218 CVSS 8.1 high A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a…
- CVE-2026-17615 CVSS 7.5 high A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote…
- CVE-2026-12894 CVSS 8.8 high A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue…
- CVE-2026-5680 CVSS 7.5 high A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with…
- CVE-2026-54513 CVSS 8.1 high jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until…