Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/apache/inlong

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-63046 is a high-severity vulnerability in Apache InLong affecting versions from 2.0.0 up to but not including 2.4.0. The flaw involves improper neutralization of argument delimiters in a command, specifically in the Agent Installer's ModuleManager component, which executes arbitrary shell commands via ExcuteLinux.exeCmd() without filtering or whitelist validation. This allows potential command injection. Users are advised to upgrade to version 2.4.0 or apply specific patches to remediate the issue.

Join the discussion

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12130 .

Join the discussion

CVE-2026-63044 is a Server-Side Request Forgery (SSRF) vulnerability in Apache InLong that allows any authenticated user, without requiring admin privileges, to make the InLong Manager server send outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This affects Apache InLong versions from 2.0.0 up to but not including 2.4.0. The issue is addressed in version 2.4.0 and can also be mitigated by applying the referenced patch from the Apache InLong GitHub repository.

Join the discussion

CVE-2026-63043 is a Relative Path Traversal vulnerability in Apache InLong that allows arbitrary file read from the Agent host filesystem. It affects versions from 2.0.0 up to but not including 2.4.0. The vulnerability has a high severity with a CVSS score of 7.5. Users are advised to upgrade to version 2.4.0 or apply the relevant patch to remediate the issue.

Join the discussion

CVE-2026-63038 is a critical SQL Injection vulnerability in Apache InLong affecting versions from 2.0.0 up to but not including 2.4.0. The flaw allows attackers to inject arbitrary SQL code via the dbName, tableName, schemaName, and username parameters. This can lead to full compromise of confidentiality, integrity, and availability of the affected system. Users are advised to upgrade to version 2.4.0 or apply the relevant patch to remediate the issue.

Join the discussion

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12095 https://github.com/apache/inlong/pull/11732

Join the discussion

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12093 https://github.com/apache/inlong/pull/11732

Join the discussion

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747

Join the discussion

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/11747

Join the discussion

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11732

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/apache/inlong
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses