securityonline.info 8/20/2026, 6:03:04 PM · external

CVE-2026-63038: Apache InLong SQL Injection Flaw Patched in 2.4.0

CVE-2026-63038: Apache InLong SQL Injection Flaw Patched in 2.4.0

APACHE InLong has patched three vulnerabilities in version 2.4.0, with the most critical being a SQL injection issue (CVE-2026-63038), alongside a path traversal flaw (CVE-2026-63043) and an authenticated SSRF vulnerability (CVE-2026-63044). No confirmed exploitation has been reported, but it is recommended to upgrade to version 2.4.0 immediately. The vulnerabilities could allow attackers to expose sensitive data and systems within the open-source data integration platform. Patching remains essential for security.

View full article

Article by CyberSIXT