Red Hat build of Apache Camel for Spring Boot

27 known vulnerabilities in Red Hat build of Apache Camel for Spring Boot, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-93574 CVSS 6.5 medium A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially…
  • CVE-2026-93562 CVSS 6.5 medium A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to…
  • CVE-2026-93579 CVSS 6.5 medium A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line…
  • CVE-2026-93576 CVSS 7.5 high A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in…
  • CVE-2026-93573 CVSS 6.5 medium A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation…
  • CVE-2026-93569 CVSS 8.2 high A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process…
  • CVE-2026-93568 CVSS 7.5 high A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended…
  • CVE-2026-93567 CVSS 7.5 high A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host…
  • CVE-2026-93566 CVSS 6.5 medium A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control…
  • CVE-2026-93565 CVSS 7.5 high A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens…
  • CVE-2026-93564 CVSS 7.5 high A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to…
  • CVE-2026-93558 CVSS 7.5 high A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using…
  • CVE-2026-93560 CVSS 7.5 high A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header…
  • CVE-2026-93492 CVSS 5.3 medium A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large…
  • CVE-2026-93491 CVSS 7.5 high A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1…
  • CVE-2026-93488 CVSS 7.5 high A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because…
  • CVE-2026-93578 CVSS 5.9 medium A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended…
  • CVE-2026-93575 CVSS 7.5 high A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted…
  • CVE-2026-93572 CVSS 7.5 high A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially…
  • CVE-2026-93563 CVSS 7.5 high A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP…
  • CVE-2026-93561 CVSS 6.5 medium A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as…
  • CVE-2026-93494 CVSS 7.5 high A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially…
  • CVE-2026-93493 CVSS 5.9 medium A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online…
  • CVE-2026-86404 CVSS 8.8 high EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses…
  • CVE-2026-84218 CVSS 8.1 high A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a…
  • CVE-2026-81624 CVSS 7.5 high Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket…
  • CVE-2026-5680 CVSS 7.5 high A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with…