A vulnerability classified as critical has been found in Apache Camel up to 4.14.5/4.18.1/4.19.x. Impacted is an unknown function of the component Incomplete Fix CVE-2025-27636. The manipulation leads to injection.

This vulnerability is documented as CVE-2026-40453. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.