CVE-2017-3159: Apache Camel
Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
Affected products
- Apache Camel: up to and including 2.14.4; from 2.17.0, up to and including 2.17.4; from 2.18.0, up to and including 2.18.1
Published 2017-03-07. Last modified 2026-06-17.