🔐 CVE Alert

CVE-2026-63043

UNKNOWN 0.0

Apache InLong: Agent path traversal via unvalidated file source path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12146 .

CWE CWE-23
Vendor apache software foundation
Product apache inlong
Published Aug 20, 2026
Last Updated Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache inlong

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache inlong are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache InLong
2.0.0 < 2.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/0ohn861tzd9g7nsosd6oz3of6dvhvqnk openwall.com: http://www.openwall.com/lists/oss-security/2026/08/20/16

Credits

dyingman1