{"api_version":"1","generated_at":"2026-08-22T05:18:58+00:00","cve":"CVE-2026-63037","urls":{"html":"https://cve.report/CVE-2026-63037","api":"https://cve.report/api/cve/CVE-2026-63037.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63037","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63037"},"summary":{"title":"Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the\nManager backend database.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12079 .","state":"PUBLISHED","assigner":"apache","published_at":"2026-08-20 16:17:29","updated_at":"2026-08-20 17:19:14"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/po2gvsl30mfjk9cy415hsbzrmqkqpd5r","name":"https://lists.apache.org/thread/po2gvsl30mfjk9cy415hsbzrmqkqpd5r","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/11","name":"http://www.openwall.com/lists/oss-security/2026/08/20/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63037","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63037","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache InLong","version":"affected 2.0.0 2.4.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"cat dg","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63037","cve":"CVE-2026-63037","epss":"0.002090000","percentile":"0.113360000","score_date":"2026-08-21","updated_at":"2026-08-22 00:12:49"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-08-20T17:09:16.069Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/11"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache InLong","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.4.0","status":"affected","version":"2.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"cat dg"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong.&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">This appears to allow SQL injection in the ORDER BY clause against the\nManager backend database.</span></p><p>This issue affects Apache InLong: from 2.0.0 before 2.4.0.</p><p></p><p><span style=\"background-color: var(--wht);\">Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.</span></p><p><span style=\"background-color: rgb(255, 255, 255);\">[1]&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/apache/inlong/issues/12079\">https://github.com/apache/inlong/issues/12079</a>.</span></p><p></p>"}],"value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the\nManager backend database.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12079 ."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-20T15:37:35.375Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/po2gvsl30mfjk9cy415hsbzrmqkqpd5r"}],"source":{"discovery":"UNKNOWN"},"title":"Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-63037","datePublished":"2026-08-20T15:37:35.375Z","dateReserved":"2026-07-15T03:06:37.120Z","dateUpdated":"2026-08-20T17:09:16.069Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-20 16:17:29","lastModifiedDate":"2026-08-20 17:19:14","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63037","Ordinal":"1","Title":"Apache InLong: Unauthenticated SQL injection in Manager OpenAPI ","CVE":"CVE-2026-63037","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63037","Ordinal":"1","NoteData":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the\nManager backend database.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12079 .","Type":"Description","Title":"Apache InLong: Unauthenticated SQL injection in Manager OpenAPI "}]}}}