CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information
Published Aug 20, 2026
·Updated
Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1]
https://github.com/apache/inlong/pull/12093 https://github.com/apache/inlong/pull/11732
Affected Software
2 affected components
Apache Inlong>2.0.0<2.4.0
Apache Inlong<2.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache InLongto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Aug 20, 2026
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Apache InLong deployments are affected?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected.
2
Who can access the exposed template information?
Users who are not responsible persons for a template can view that template's information.
3
What should teams do to remediate the issue?
Upgrade Apache InLong to version 2.4.0, or cherry-pick the referenced fixes.