
CVE-2026-40859
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Reproducer for CVE-2026-43866 — Apache Camel camel-jms forged DefaultExchangeHolder bypass of the CVE-2026-40860 deserialization filter…

Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

Proof-of-concept demonstrating remote code execution in Apache Camel by exploiting header and parameter filtering bypasses (CVE-2025-27636,…

Runnable proof-of-concept reproducer for CVE-2026-88789, demonstrating XXE and SSRF in Apache Camel Quarkus camel-quarkus-support-xalan via the XSLT…

Provides working proof-of-concept exploits and detailed analysis for three critical Apache Camel vulnerabilities, including CoAP header injection and…

PoC reproducer for CVE-2026-49086 demonstrating a confused-deputy routing-header override in Apache Camel camel-dapr, enabling message redirection…

Proof-of-concept reproducers for Apache Camel camel-knative structured CloudEvent header injection (CVE-2026-63621), demonstrating header injection…

Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal

Proof-of-concept reproducers for Apache Camel camel-google-storage path traversal (CVE-2026-66907), demonstrating arbitrary file write via…

Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via…

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the…

Professional vulnerability assessment report for Apache Camel Docling argument validation risk, including technical impact, remediation, and…

Proof-of-concept exploit for CVE-2014-8110, a remote code execution vulnerability in Apache Camel. Demonstrates exploitation of the flaw for security…