Messages by Thread
-
[VOTE] Release Camel Kafka Connector 4.22.0
Andrea Cosentino
-
[VOTE] Release Apache Camel Kamelets 4.22.1
Andrea Cosentino
-
[RESULT][VOTE] Release Apache Camel Quarkus 3.33.3
Jiří Ondrušek
-
[ANNOUNCE] Apache Camel 4.22.1 (LTS) Released
Gregor Zurowski
-
Hackathon at Community over Code Glasgow — schedule slot needed
Rich Bowen
-
Appeal regarding denied Jira account request - [email protected]
Hesanda Nimneth
-
[ANNOUNCE] Apache Camel Karaf 4.18.4 has been released!
Jean-Baptiste Onofré
-
[VOTE] Release Apache Camel Quarkus 3.33.3
Jiří Ondrušek
-
[VOTE] Release Apache Camel 4.22.1 (LTS)
Gregor Zurowski
-
[VOTE] Release Apache Camel Karaf 4.18.4
Jean-Baptiste Onofré
-
Upgrade guides ONLY on main
Claus Ibsen
-
New Apache Camel website front page
Claus Ibsen
-
Hackathon room schedule — please claim your slot
Rich Bowen
-
[REPORT] Monthly Camel static code analysis - 2026/08
Pasquale Congiusti
-
Camel 4.22.1 patch release
Claus Ibsen
-
[VOTE] Release Apache Camel K 2.11.0, 2.10.2 and 2.9.3
Pasquale Congiusti
-
GitHub CI Usage - August 2026
Aurelien Pupier via dev
-
Customize 404/405 response body when using REST OpenApi component
Pontus Ullgren
-
[RESULT] [VOTE] Release Apache Camel Upgrade Recipes 4.22.0
Jiří Ondrušek
-
[VOTE] Release Apache Camel Upgrade Recipes 4.22.0
Jiří Ondrušek
-
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Andrea Cosentino
-
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Andrea Cosentino
-
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Andrea Cosentino
-
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
Andrea Cosentino
-
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Andrea Cosentino
-
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Andrea Cosentino
-
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Andrea Cosentino
-
[VOTE] Release Apache Camel Kamelets 4.22.0
Andrea Cosentino
-
[RESULT][VOTE] Release Apache Camel Quarkus 3.39.0
Jiří Ondrušek
-
[VOTE] Release Apache Camel Quarkus 3.39.0
Jiří Ondrušek
-
Community over Code Glasgow 2026 Hackathon - Action Needed
Bowen, Rich
-
[ANNOUNCE] Apache Camel 4.18.4 (LTS) Released
Gregor Zurowski
-
[ANNOUNCE] Apache Camel 4.14.9 (LTS) Released
Gregor Zurowski
-
[ANNOUNCE] Apache Camel 4.22.0 (LTS) Released
Gregor Zurowski
-
[VOTE] Release Apache Camel 4.18.4 (LTS)
Gregor Zurowski
-
[VOTE] Release Apache Camel 4.14.9 (LTS)
Gregor Zurowski
-
[FEEDBACK] - Blog whats new 4.22
Claus Ibsen
-
Camel patch releases 4.18.4 and 4.14.9
Claus Ibsen
-
[VOTE] Release Apache Camel 4.22.0 (LTS)
Gregor Zurowski
-
Hackathon task list needed - 10 weeks out
Bowen, Rich
-
Introduction - integration engineer interested in contributing, healthcare components
vishal khobare
-
GitHub CI Usage - July 2026
Aurelien Pupier via dev
-
[REPORT] Monthly Camel static code analysis - 2026/07
Pasquale Congiusti
-
[RESULT][VOTE] Release Apache Camel Quarkus 3.38.0
James Netherton
-
[VOTE] Release Apache Camel Quarkus 3.38.0
James Netherton
-
[RESULT] [VOTE] Release Apache Camel Upgrade Recipes 4.21.0
Jiří Ondrušek
-
CAMEL-23382: Unified AI tool abstraction (camel-ai-tool) - Heads-up
Zineb Bendhiba
-
[VOTE] Release Apache Camel Upgrade Recipes 4.21.0
Jiří Ondrušek
-
[VOTE] Release Apache Camel Kamelets 4.18.3
Andrea Cosentino
-
[RESULT][VOTE] Release Apache Camel Quarkus 3.33.2
Jiří Ondrušek
-
[RESULT][VOTE] Release Apache Camel Quarkus 3.27.5
Jiří Ondrušek
-
[VOTE] Release Apache Camel Quarkus 3.33.2
Jiří Ondrušek
-
[VOTE] Release Apache Camel Quarkus 3.27.5
Jiří Ondrušek
-
CVE-2026-49042: Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
Federico Mariani
-
CVE-2026-46588: Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Federico Mariani
-
CVE-2026-46587: Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Federico Mariani
-
CVE-2026-43867: Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
Andrea Cosentino
-
CVE-2026-43866: Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
Andrea Cosentino
-
CVE-2026-42527: Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
Andrea Cosentino
-
CVE-2026-46453: Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
Andrea Cosentino
-
CVE-2026-43865: Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
Andrea Cosentino
-
CVE-2026-46454: Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
Andrea Cosentino
-
CVE-2026-46455: Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
Andrea Cosentino
-
CVE-2026-46456: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
Andrea Cosentino
-
CVE-2026-46457: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
Andrea Cosentino
-
CVE-2026-46584: Apache Camel: Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties, allowing an attacker to weaken the SMTP transport security and, on releases before 4.19.0, redirect the connection and steal
Andrea Cosentino
-
CVE-2026-46585: Apache Camel: Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
Andrea Cosentino
-
CVE-2026-46590: Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
Andrea Cosentino
-
CVE-2026-46591: Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
Andrea Cosentino
-
CVE-2026-46592: Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
Andrea Cosentino
-
CVE-2026-46726: Apache Camel: Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling server-side request forgery and disclosure of
Andrea Cosentino
-
CVE-2026-48204: Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
Andrea Cosentino
-
CVE-2026-48203: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Andrea Cosentino
-
CVE-2026-48205: Apache Camel: Camel-DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect DNS queries to an attacker-controlled server (server-side request forgery) and enumerate internal
Andrea Cosentino
-
CVE-2026-48206: Apache Camel: Camel-JIRA: A set of non-Camel-prefixed Exchange header constants (IssueKey, ProjectKey, IssueTransitionId, ...) bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
Andrea Cosentino
-
CVE-2026-49086: Apache Camel: Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to redirect the re-published message to an arbitrary Dapr Pub/Su
Andrea Cosentino
-
CVE-2026-49098: Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic
Andrea Cosentino
-
CVE-2026-49097: Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users
Andrea Cosentino