CVE-2025-66169
Apache Camel camel-neo4j component is vulnerable to cypher injection
EPSS 0.03%
Description
Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
How to fix CVE-2025-66169
To remediate CVE-2025-66169, upgrade the affected package to a fixed version below.
- Maven/org.apache.camel:camel-neo4j—upgrade to 4.10.8 or later
Is CVE-2025-66169 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 4.10.0, < 4.10.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |