{"id":"GHSA-4jrw-64vr-7g8m","summary":"Apache Camel camel-neo4j component is vulnerable to cypher injection","details":"Cypher Injection vulnerability in Apache Camel camel-neo4j component.\n\nThis issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0\n\nUsers are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.","aliases":["CVE-2025-66169"],"modified":"2026-02-03T03:18:12.507359Z","published":"2026-01-14T12:31:38Z","database_specific":{"github_reviewed_at":"2026-01-14T21:17:27Z","nvd_published_at":"2026-01-14T12:16:32Z","cwe_ids":["CWE-74","CWE-89","CWE-943"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66169"},{"type":"WEB","url":"https://github.com/apache/camel/pull/20035"},{"type":"WEB","url":"https://github.com/apache/camel/pull/20036"},{"type":"WEB","url":"https://github.com/apache/camel/pull/20037"},{"type":"WEB","url":"https://github.com/apache/camel/commit/66715d3feb4ba15df30cffe437e45efeedfba10d"},{"type":"WEB","url":"https://github.com/apache/camel/commit/723e2cd98ce4b4ceb1dd38837bc113fca0cef170"},{"type":"WEB","url":"https://github.com/apache/camel/commit/e46c4c0ef542a64dc791253763a8273dfd7fb179"},{"type":"WEB","url":"https://camel.apache.org/security/CVE-2025-66169.html"},{"type":"PACKAGE","url":"https://github.com/apache/camel"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/CAMEL-22719"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/01/13/5"}],"affected":[{"package":{"name":"org.apache.camel:camel-neo4j","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-neo4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"4.10.8"}]}],"versions":["4.10.0","4.10.1","4.10.2","4.10.3","4.10.4","4.10.5","4.10.6","4.10.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4jrw-64vr-7g8m/GHSA-4jrw-64vr-7g8m.json"}},{"package":{"name":"org.apache.camel:camel-neo4j","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-neo4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.14.0"},{"fixed":"4.14.3"}]}],"versions":["4.14.0","4.14.1","4.14.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4jrw-64vr-7g8m/GHSA-4jrw-64vr-7g8m.json"}},{"package":{"name":"org.apache.camel:camel-neo4j","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-neo4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.17.0"}]}],"versions":["4.15.0","4.16.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4jrw-64vr-7g8m/GHSA-4jrw-64vr-7g8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}