Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache InLong — Vulnerabilities & Security Advisories 41

All 41 CVE vulnerabilities found in Apache InLong, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Apache InLong, a distributed data ingestion platform maintained by the Apache Software Foundation. The collection compiles security advisories and weakness classifications, covering vulnerabilities reported from the product’s initial release through the most recent stable version. Readers can use this aggregation to track the vendor’s advisory history, analyze recurring weakness patterns such as path traversal or deserialization issues, and review the complete vulnerability lifecycle for this specific data pipeline product.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-63046 Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials CWE-88 - - 2026-08-21
CVE-2026-63044 Apache InLong: Authenticated SSRF via POST /api/node/testConnection CWE-918 - - 2026-08-20
CVE-2026-63043 Apache InLong: Agent path traversal via unvalidated file source path CWE-23 - - 2026-08-20
CVE-2026-63042 Apache InLong: Missing authorization on DataNode management endpoints CWE-552 - - 2026-08-20
CVE-2026-63040 Apache InLong: Missing authorization in StreamSource forceDelete CWE-552 - - 2026-08-20
CVE-2026-63039 Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService CWE-89 - - 2026-08-20
CVE-2026-63038 Apache InLong: SQL Injection via String Concatenation Vulnerability Report CWE-89 - - 2026-08-20
CVE-2026-63037 Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint CWE-89 - - 2026-08-20
CVE-2026-63016 Apache InLong: Ordinary users can create new packages CWE-400 - - 2026-08-20
CVE-2026-63015 Apache InLong: Non-template responsible persons can view template information CWE-400 - - 2026-08-20
CVE-2025-27531 Apache InLong: An arbitrary file read vulnerability for JDBC CWE-502 6.5AI Medium AI 2025-06-06
CVE-2025-27528 Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read CWE-502 7.5AI High AI 2025-05-28
CVE-2025-27526 Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass CWE-502 9.8AI Critical AI 2025-05-28
CVE-2025-27522 Apache InLong: JDBC Vulnerability during verification processing CWE-502 8.1AI High AI 2025-05-28
CVE-2024-26579 Apache Inlong JDBC Vulnerability CWE-502 9.8AI Critical AI 2024-05-08
CVE-2024-26580 Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability CWE-502 9.1AI Critical AI 2024-03-06
CVE-2023-51784 Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager CWE-94 9.8AI Critical AI 2024-01-03
CVE-2023-51785 Apache InLong: Arbitrary File Read Vulnerability in Apache InLong Manager CWE-502 7.5AI High AI 2024-01-03
CVE-2023-46227 Apache inlong has an Arbitrary File Read Vulnerability CWE-502 9.8 - 2023-10-19
CVE-2023-43666 Apache InLong: General user Unauthorized access User Management CWE-345 6.5 - 2023-10-16
CVE-2023-43667 Apache InLong: Log Injection in Global functions CWE-74 5.3 - 2023-10-16
CVE-2023-43668 Apache InLong: Jdbc Connection Security Bypass in InLong CWE-639 9.8 - 2023-10-16
CVE-2023-35088 Apache InLong: SQL injection in audit endpoint CWE-89 9.8 - 2023-07-25
CVE-2023-34434 Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param CWE-502 7.5 - 2023-07-25
CVE-2023-34189 Apache InLong: General user can delete and update process CWE-668 9.1 - 2023-07-25
CVE-2023-31062 Apache InLong: Privilege escalation vulnerability for InLong CWE-269 8.8 - 2023-05-22
CVE-2023-31064 Apache InLong: Insecurity direct object references cancelling applications CWE-552 6.5 - 2023-05-22
CVE-2023-31065 Apache InLong: Insufficient Session Expiration in InLong CWE-613 9.8 - 2023-05-22
CVE-2023-31066 Apache InLong: Insecure direct object references for inlong sources CWE-552 8.1 - 2023-05-22
CVE-2023-31098 Apache InLong: Weak Password Implementation in InLong CWE-521 7.4 - 2023-05-22

All 41 known CVE vulnerabilities affecting Apache InLong with full Chinese analysis, references, and POCs where available.