PT-2026-2851 · Apache+1 · Apache Camel+2

Ya0H4Cker

·

Published

2026-01-14

·

Updated

2026-01-15

·

CVE-2025-66169

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Camel versions 4.10.0 through 4.10.7 Apache Camel versions 4.14.0 through 4.14.2 Apache Camel versions 4.15.0 through 4.16.9
Description A Cypher Injection issue exists in the Apache Camel camel-neo4j component. This allows for potential unauthorized access or manipulation of data within a Neo4j database. The issue stems from insufficient input validation when processing Cypher queries. The component is susceptible to malicious Cypher code injection through user-supplied input.
Recommendations Upgrade to Apache Camel version 4.10.8 Upgrade to Apache Camel version 4.14.3 Upgrade to Apache Camel version 4.17.0

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-66169
GHSA-4JRW-64VR-7G8M

Affected Products

Apache Camel
Neo4J
Camel-Neo4J