CVE-2025-66169: Apache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component
Published Jan 13, 2026
·Updated
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Affected Software
7 affected componentsFixes available
Apache Camel>4.10.0<4.10.8, >4.14.0<4.14.3, >4.15.0<4.17.0
maven/org.apache.camel:camel-neo4j>=4.15.0<4.17.0
4.17.0
maven/org.apache.camel:camel-neo4j>=4.14.0<4.14.3
4.14.3
maven/org.apache.camel:camel-neo4j>=4.10.0<4.10.8
4.10.8
Apache Camel>=4.10.0<4.10.8
Apache Camel>=4.14.0<4.14.3
Apache Camel>=4.15.0<4.17.0
Event History
Jan 14, 2026
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
Are there any workarounds for CVE-2025-66169?
Currently, there are no known workarounds for CVE-2025-66169 other than upgrading to the patched versions.