Executive brief
Apache InLong is an open-source data integration platform used to manage real-time data pipelines and configurations. This vulnerability allows ordinary users to upload non-official packages and affect operational configuration through uncontrolled resource consumption, potentially disrupting service availability or introducing unauthorized code into the system.
Technical details
This is an uncontrolled resource consumption vulnerability in Apache InLong affecting versions 2.0.0 through 2.4.0. The root cause stems from insufficient validation of package uploads and configuration changes, allowing authenticated (ordinary) users to consume excessive resources or upload unauthorized packages. The attack requires network access to InLong and valid user credentials. An attacker can exploit this to disrupt service operations or inject non-official packages for code execution. Fixes are available in version 2.4.0 or via cherry-picking patches from the referenced GitHub pull requests.
Affected products
- Apache InLong 2.0.0 to before 2.4.0
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fixed in version 2.4.0