https://seclists.org/oss-sec/2026/q3/531: CVE-2026-63016: Apache InLong: Ordinary users can cate new packages
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
Apache Inlong>2.0.0<=2.4.0
Frequently Asked Questions
1
Which Apache InLong deployments require remediation?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected. Version 2.4.0 is identified as the fixed release.
2
What can be done if an immediate upgrade is not possible?
The advisory recommends upgrading to Apache InLong 2.4.0 or cherry-picking the referenced upstream changes from pull requests 12095 and 11732.