Critical severity9.8NVD Advisory· Published Aug 20, 2026· Updated Aug 26, 2026
CVE-2026-63037
CVE-2026-63037
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/issues/12079 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/20/11nvdMailing ListThird Party Advisory
- lists.apache.org/thread/po2gvsl30mfjk9cy415hsbzrmqkqpd5rnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.