Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to
arbitrary internal hosts and ports.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12130 .
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/b3rtzssd8hdk0dyq4y6mpdx6jj5ro4g6 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/08/20/17 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-20 16:17
Updated : 2026-08-27 00:03
NVD link : CVE-2026-63044
Mitre link : CVE-2026-63044
CVE.ORG link : CVE-2026-63044
JSON object : View
Products Affected
apache
- inlong
CWE
CWE-918
Server-Side Request Forgery (SSRF)
