Cypher Injection vulnerability in Apache Camel camel-neo4j component.

This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0

Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4jrw-64vr-7g8m Apache Camel camel-neo4j component is vulnerable to cypher injection
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 19 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 16 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*

Thu, 15 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache camel
Vendors & Products Apache
Apache camel

Wed, 14 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 14 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Title Apache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-15T20:43:58.492Z

Reserved: 2025-11-22T15:52:31.739Z

Link: CVE-2025-66169

cve-icon Vulnrichment

Updated: 2026-01-14T12:09:49.092Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-14T12:16:32.257

Modified: 2026-01-16T14:29:11.873

Link: CVE-2025-66169

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-14T11:45:20Z

Links: CVE-2025-66169 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-15T08:03:49Z

Weaknesses