PT-2026-2851 · Apache+1 · Camel-Neo4J+2

·

CVE-2025-66169

·

Published

2026-01-14

·

Updated

2026-07-06

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Camel versions 4.10.0 through 4.10.7 Apache Camel versions 4.14.0 through 4.14.2 Apache Camel versions 4.15.0 through 4.16.9
Description A Cypher Injection issue exists in the Apache Camel camel-neo4j component. This allows for potential unauthorized access or manipulation of data within a Neo4j database. The issue stems from insufficient input validation when processing Cypher queries. The component is susceptible to malicious Cypher code injection through user-supplied input.
Recommendations Upgrade to Apache Camel version 4.10.8 Upgrade to Apache Camel version 4.14.3 Upgrade to Apache Camel version 4.17.0

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66169
GHSA-4JRW-64VR-7G8M

Affected Products

Apache Camel
Neo4J
Camel-Neo4J