CVE-2015-5344: Apache Camel

Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Affected products

  • Apache Camel: up to and including 2.15.4; version 2.16.0 only

Published 2016-02-03. Last modified 2026-06-17.