SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-63044

MEDIUM · CVSS 5.4 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery (SSRF) vulnerability in Apache InLong allows any authenticated user, regardless of their role, to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This could lead to unauthorized access to sensitive internal services and data. Organizations using affected versions of Apache InLong (2.0.0 to 2.4.0) should prioritize upgrading to version 2.4.0 or apply the provided patch to mitigate this risk.

CVE
CVE-2026-63044
Severity
MEDIUM
CVSS
5.4
EPSS
0.44%
Apache GitHub

Original NVD Description

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12130 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)