Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
References
| Link | Resource |
|---|---|
| https://camel.apache.org/security/CVE-2025-66169.html | Mailing List Vendor Advisory Issue Tracking |
| http://www.openwall.com/lists/oss-security/2026/01/13/5 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jan 2026, 14:29
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | |
| References | () https://camel.apache.org/security/CVE-2025-66169.html - Mailing List, Vendor Advisory, Issue Tracking | |
| References | () http://www.openwall.com/lists/oss-security/2026/01/13/5 - Mailing List, Third Party Advisory | |
| First Time |
Apache
Apache camel |
15 Jan 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
14 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jan 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-14 12:16
Updated : 2026-01-16 14:29
NVD link : CVE-2025-66169
Mitre link : CVE-2025-66169
CVE.ORG link : CVE-2025-66169
JSON object : View
Products Affected
apache
- camel
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
