Critical 1 vendor · 4 advisories
CVE-2025-27636
CVE-2025-27636: critical-severity vulnerability covered by 4 tracked advisory records across Apache. Compare affected products, fixed versions and remediation.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Apache4 advisories
- Critical9.4Critical [CVE-2025-27636 +3] Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)Apr 27, 2026
- Critical9.9Critical [CVE-2025-27636 +1] Apache Camel: The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as…Apr 27, 2026
- UnratedUnknown [CVE-2025-27636 +4] Apache Camel: Camel-CXF Message Header Injection via Missing Inbound FilteringMay 19, 2026
- UnratedUnknown [CVE-2025-27636 +5] Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headersAug 24, 2026