CVE-2026-63016: Apache InLong: Ordinary users can create new packages
Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1]
https://github.com/apache/inlong/pull/12095 https://github.com/apache/inlong/pull/11732
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache InLongto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Frequently Asked Questions
Which Apache InLong versions are affected?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected.
What level of access does an attacker need?
An ordinary authenticated user can create new packages. This can affect operational configuration or permit uploads of non-official packages.
What is the recommended remediation?
Upgrade Apache InLong to version 2.4.0. If upgrading is not immediately possible, cherry-pick the referenced fixes in pull requests 12095 and 11732.