CVE-2025-66169

Source
https://cve.org/CVERecord?id=CVE-2025-66169
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66169.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66169
Aliases
Published
2026-01-14T11:45:20.338Z
Modified
2026-07-15T01:49:17.385358562Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Apache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component
Details

Cypher Injection vulnerability in Apache Camel camel-neo4j component.

This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0

Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.10.0"
                },
                {
                    "fixed": "4.10.8"
                },
                {
                    "introduced": "4.14.0"
                },
                {
                    "fixed": "4.14.3"
                },
                {
                    "introduced": "4.15.0"
                },
                {
                    "fixed": "4.17.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "4.10.0"
                },
                {
                    "fixed": "4.10.8"
                },
                {
                    "introduced": "4.14.0"
                },
                {
                    "fixed": "4.14.3"
                },
                {
                    "introduced": "4.15.0"
                },
                {
                    "fixed": "4.17.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66169.json"
}
References

Affected packages

Git / github.com/apache/camel

Affected ranges

Type
GIT
Repo
https://github.com/apache/camel
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.10.0"
        },
        {
            "fixed": "4.10.8"
        },
        {
            "introduced": "4.14.0"
        },
        {
            "fixed": "4.14.3"
        },
        {
            "introduced": "4.15.0"
        },
        {
            "fixed": "4.17.0"
        }
    ],
    "cpe": "cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66169.json"