---
id: CVE-2026-80352
title: >-
  Improper Control of Generation of Code ('Code Injection') vulnerability in
  Apache Camel K.




  A YAML injection vulnerability in custom resource configuration allows an
  authorized CR author to inject arbitrary Kubernetes objects, potentia…
summary: >-
  Improper Control of Generation of Code ('Code Injection') vulnerability in
  Apache Camel K.




  A YAML injection vulnerability in custom resource configuration allows an
  authorized CR author to inject arbitrary Kubernetes objects, potentia…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: apache
product: camel
affected:
  - 'camel >= 2.0.0, < 2.9.3'
  - 'camel >= 2.10.0, < 2.10.2'
patched:
  - camel 2.10.2
published: '2026-09-10'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T19:57:07.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80352'
references:
  - url: 'https://camel.apache.org/security/CVE-2026-80352.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/10/15'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00445
epssPercentile: 0.38084
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-10T15:58:34.590571Z'
ingestedAt: '2026-09-12T20:09:17.225Z'
---

## Overview

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.



A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.



This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.



Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

## Affected

- `camel >= 2.0.0, < 2.9.3`
- `camel >= 2.10.0, < 2.10.2`

## Remediation

Upgrade past the affected range:

- `camel 2.10.2`
