CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.