CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12080 .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache InLongto a version that resolves this vulnerability.Fixed in 2.4.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 12080
Event History
Frequently Asked Questions
Which Apache InLong versions are affected?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected.
What remediation is available?
Upgrade Apache InLong to version 2.4.0. As an alternative, users can cherry-pick the referenced fix pull request.