https://seclists.org/oss-sec/2026/q3/564: CVE-2026-66906: Apache Camel: Camel-Azu-Storage-Blob: the downloadBlobToFile operation built the local download target from the mote blob name without constraining it to the configud fileDir
Published Aug 24, 2026
·Updated
Affected Software
1 affected component
Apache Camel camel-azure-storage-blob>4.0.0<4.14.9, >4.15.0<4.18.4, >4.19.0<4.22.0