Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
References
| Link | Resource |
|---|---|
| https://camel.apache.org/security/CVE-2025-66169.html | Mailing List Vendor Advisory Issue Tracking |
| http://www.openwall.com/lists/oss-security/2026/01/13/5 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-14 12:16
Updated : 2026-01-16 14:29
NVD link : CVE-2025-66169
Mitre link : CVE-2025-66169
CVE.ORG link : CVE-2025-66169
JSON object : View
Products Affected
apache
- camel
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
