https://seclists.org/oss-sec/2025/q2/170: CVE-2025-27526: Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
Published May 28, 2025
·Updated
Affected Software
1 affected component
Apache Inlong>=1.13.0<=2.1.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27526?
The severity of CVE-2025-27526 is classified as moderate.
2
What versions of Apache InLong are affected by CVE-2025-27526?
Apache InLong versions from 1.13.0 through 2.1.0 are affected by CVE-2025-27526.
3
What type of vulnerability is CVE-2025-27526?
CVE-2025-27526 is a deserialization of untrusted data vulnerability.
4
How do I fix CVE-2025-27526?
To fix CVE-2025-27526, upgrade Apache InLong to a version later than 2.1.0.
5
What does CVE-2025-27526 allow an attacker to do?
CVE-2025-27526 can lead to a JDBC vulnerability allowing for URL encoding and backspace bypass.