Sceawere

Vulnerability Detail

CVE-2026-63015UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache InLong Resource Consumption Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
Apache Software Foundation
Product
Apache InLong
Attack Type
CWE-400 Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12093 https://github.com/apache/inlong/pull/11732

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-20T16:17:28.557Z",
  "pubdate": "2026-08-20T16:17:28.557Z",
  "executiveSummary": "An Uncontrolled Resource Consumption vulnerability has been identified in Apache InLong, which also involves unauthorized access to template information by non-template responsible persons.\nThis security flaw affects Apache InLong versions ranging from 2.0.0 prior to 2.4.0.\nThe vulnerability allows unauthorized users to view sensitive template information and potentially trigger excessive resource consumption against the underlying system.\nThe risk implications include potential information disclosure regarding internal template structures and degradation of service availability due to unconstrained resource utilization.\nAttackers require network access to the vulnerable Apache InLong deployment to leverage these flaws.\nUsers and administrators are strongly advised to apply the provided vendor patches or upgrade to the fixed version to mitigate potential exploitation vectors.",
  "technicalDetails": "The vulnerability resides within Apache InLong components responsible for managing and processing template information and resource allocation.\nSpecifically, the access control mechanisms fail to properly validate whether a user holds template-responsible privileges before granting visibility into template data.\nAdditionally, the system lacks adequate bounds or rate-limiting controls on resource-intensive operations, leading to an Uncontrolled Resource Consumption condition.\nThe affected software versions include Apache InLong from 2.0.0 before 2.4.0.\nDuring an attack, an unprivileged or improperly authorized user sends specially crafted requests targeting template information endpoints.\nBecause privilege checks are missing or improperly enforced for non-template responsible persons, the application processes the request and discloses sensitive template data.\nSimultaneously, repeated or heavy queries exploiting the unconstrained resource consumption vector can overwhelm system memory, CPU, or I/O channels.\nThe attack flow proceeds with the malicious actor interacting directly over the network protocol utilized by Apache InLong services, bypassing intended authorization boundaries without requiring elevated administrative privileges.\nPost-exploitation impact includes unauthorized intelligence gathering regarding workflow templates and potential denial-of-service conditions affecting the broader data integration pipeline managed by Apache InLong."
}
CVE-2026-63015: Apache InLong Resource Consumption Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere