CVE-2025-27526: Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
Other sources
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncode and backspace bypass. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27526?
CVE-2025-27526 is classified as a critical vulnerability due to its potential to lead to severe exploitation like JDBC vulnerability and backspace bypass.
How do I fix CVE-2025-27526?
To mitigate CVE-2025-27526, users should upgrade to Apache InLong version 2.2.0 or apply specific cherry-picking patches as necessary.
What versions of Apache InLong are affected by CVE-2025-27526?
CVE-2025-27526 affects Apache InLong versions from 1.13.0 to 2.1.0.
What kind of data vulnerability is CVE-2025-27526?
CVE-2025-27526 is a deserialization of untrusted data vulnerability.
What are the potential consequences of CVE-2025-27526?
The potential consequences of CVE-2025-27526 include unauthorized manipulation of data leading to security breaches.