Skip to content

chore(deps): FORGE-632 upgrade Apache Camel to 4.14.6 to remediate CVEs - #27

Open
joeyliechty wants to merge 1 commit into
developfrom
FORGE-632
Open

joeyliechty wants to merge 1 commit into
developfrom
FORGE-632

Conversation

@joeyliechty

Copy link
Copy Markdown
Contributor

Addresses 7 CVEs in camel-core (4.14.4) including one RCE-class vulnerability (CVE-2026-33454, CVE-2026-40022, CVSS 6.9). Upgrade to 4.14.6 is the safe LTS patch that resolves all reported issues without entering the 4.18/4.19 ranges affected by CVE-2026-40048.
Bumps camel.version in both the plugin (pom.xml) and demo (demo/pom.xml).

(co-authored with Claude Code)

Addresses 7 CVEs in camel-core (4.14.4) including one RCE-class vulnerability
(CVE-2026-33454, CVE-2026-40022, CVSS 6.9). Upgrade to 4.14.6 is the safe
LTS patch that resolves all reported issues without entering the 4.18/4.19
ranges affected by CVE-2026-40048.
Bumps camel.version in both the plugin (pom.xml) and demo (demo/pom.xml).

(co-authored with Claude Code)
@github-actions

Copy link
Copy Markdown
Contributor

There is no coverage information present for the Files changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant