2026 CVE Vulnerabilities
59,167 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49097 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject... |
| CVE-2026-49086 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR compo... |
| CVE-2026-48206 | MEDIUM | 5.3 | 0.2% | Jul 6, 2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component... |
| CVE-2026-48205 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn... |
| CVE-2026-48204 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The... |
| CVE-2026-48203 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid... |
| CVE-2026-46726 | HIGH | 7.5 | 0.4% | Jul 6, 2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF... |
| CVE-2026-46592 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c... |
| CVE-2026-46591 | HIGH | 8.2 | 0.2% | Jul 6, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The came... |
| CVE-2026-46590 | HIGH | 8.8 | 0.4% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu... |
| CVE-2026-46585 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone... |
| CVE-2026-46584 | LOW | 3.7 | 0.2% | Jul 6, 2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail... |
| CVE-2026-46457 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess... |
| CVE-2026-46456 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m... |
| CVE-2026-46455 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke... |
| CVE-2026-46454 | CRITICAL | 9.8 | 0.4% | Jul 6, 2026 | Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu... |
| CVE-2026-46453 | MEDIUM | 5.3 | 0.2% | Jul 6, 2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch ... |
| CVE-2026-44934 | HIGH | 7 | 0.1% | Jul 6, 2026 | A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM... |
| CVE-2026-43867 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu... |
| CVE-2026-43866 | HIGH | 7.3 | 0.2% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom... |
| CVE-2026-43865 | HIGH | 8.1 | 0.5% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea... |
| CVE-2026-42527 | HIGH | 8.1 | 0.3% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev... |
| CVE-2026-40859 | HIGH | 8.1 | 0.5% | Jul 6, 2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo... |
| CVE-2026-40047 | CRITICAL | 9.1 | 1.3% | Jul 6, 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling... |
| CVE-2026-24014 | CRITICAL | 9.8 | 0.4% | Jul 6, 2026 | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now