CVE-2026-63044

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12130 .
References
Link Resource
https://lists.apache.org/thread/b3rtzssd8hdk0dyq4y6mpdx6jj5ro4g6 Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/08/20/17 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-20 16:17

Updated : 2026-08-27 00:03


NVD link : CVE-2026-63044

Mitre link : CVE-2026-63044

CVE.ORG link : CVE-2026-63044


JSON object : View

Products Affected

apache

  • inlong
CWE
CWE-918

Server-Side Request Forgery (SSRF)