| 严重 |
—— |
| 未审查 |
| 2026-08-25 02:31 |
| 2026-08-25 02:31 |
| GHSA-W7R2-CXJQ-9W33 CVE-2026-15469 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-VVWM-3J43-7PFM CVE-2026-63621 | Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy | 中危 | Mavenorg.apache.camel:camel-knative | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:30 |
| GHSA-V32J-VGQH-F22G CVE-2026-67204 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-MX2Q-89WP-JRVH CVE-2026-76071 | 无摘要 | 严重 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-M5R8-W65Q-8WJF CVE-2026-71300 | Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace | 严重 | Mavenorg.apache.camel:camel-atmosphere-websocket | 已审查 | 2026-08-25 02:31 | 2026-08-29 06:00 |
| GHSA-FPM2-M4QQ-WGHR CVE-2026-66908 | Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted | 高危 | Mavenorg.apache.camel:camel-platform-http-main | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:56 |
| GHSA-F78G-9385-QXQJ CVE-2026-66907 | Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result | 高危 | Mavenorg.apache.camel:camel-google-storage | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:55 |
| GHSA-CX47-QXP5-MMH2 CVE-2026-59230 | Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled | 中危 | Mavenorg.apache.camel:camel-mail | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:19 |
| GHSA-C8M2-HM25-9JF6 CVE-2025-36940 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-8VQH-RJH4-52QH CVE-2026-71366 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 17:30 |
| GHSA-8C5X-7FMX-F5J4 CVE-2026-18349 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-7JWC-Q3FJ-C9PQ CVE-2026-60093 | Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir | 中危 | Mavenorg.apache.camel:camel-azure-storage-datalake | 已审查 | 2026-08-25 02:31 | 2026-08-29 04:29 |
| GHSA-7GC7-3GXP-V85M CVE-2026-76070 | 无摘要 | 严重 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-6V7V-PP54-GR28 CVE-2026-71364 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 17:30 |
| GHSA-5XJJ-33WR-W9J3 CVE-2026-75099 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-4GHJ-75G5-H9PF CVE-2026-78416 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-27 08:30 |
| GHSA-2X37-89HJ-2J95 CVE-2026-66906 | Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir | 严重 | Mavenorg.apache.camel:camel-azure-storage-blob | 已审查 | 2026-08-25 02:31 | 2026-08-29 05:54 |
| GHSA-XPCX-M92F-XJ7Q CVE-2025-68825 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-VW7C-29JJ-VH2H CVE-2026-12556 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-09-04 02:31 |
| GHSA-9JPQ-GP3P-PV2F CVE-2026-12555 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-09-04 02:31 |
| GHSA-7WVW-8J5R-XV28 CVE-2026-12554 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-09-04 02:31 |
| GHSA-72WG-WPG2-8V59 CVE-2026-21752 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 02:31 | 2026-08-25 02:31 |
| GHSA-W97J-4P5M-Q72W CVE-2026-78387 | 无摘要 | 严重 | —— | 未审查 | 2026-08-24 23:31 | 2026-08-24 23:31 |