{"api_version":"1","generated_at":"2026-08-22T05:19:08+00:00","cve":"CVE-2026-63038","urls":{"html":"https://cve.report/CVE-2026-63038","api":"https://cve.report/api/cve/CVE-2026-63038.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63038","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63038"},"summary":{"title":"Apache InLong: SQL Injection via String Concatenation Vulnerability Report","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the\ndbName, tableName, schemaName, and username parameters. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12135 .","state":"PUBLISHED","assigner":"apache","published_at":"2026-08-20 16:17:29","updated_at":"2026-08-20 17:19:14"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/12","name":"http://www.openwall.com/lists/oss-security/2026/08/20/12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/79w0cfnkhs3hctv8yn861qx3qwlc3p37","name":"https://lists.apache.org/thread/79w0cfnkhs3hctv8yn861qx3qwlc3p37","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63038","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63038","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache InLong","version":"affected 2.0.0 2.4.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"zhaokaifei","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63038","cve":"CVE-2026-63038","epss":"0.002050000","percentile":"0.108220000","score_date":"2026-08-21","updated_at":"2026-08-22 00:12:49"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-08-20T17:09:17.259Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/12"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache InLong","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.4.0","status":"affected","version":"2.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"zhaokaifei"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. <span style=\"background-color: rgb(255, 255, 255);\">This allows an attacker to inject arbitrary SQL code through the\ndbName, tableName, schemaName, and username parameters.&nbsp;</span></p><p>This issue affects Apache InLong: from 2.0.0 before 2.4.0.</p><p></p><p><span style=\"background-color: var(--wht);\">Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.</span></p><p><span style=\"background-color: rgb(255, 255, 255);\">[1]&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/apache/inlong/issues/12135\">https://github.com/apache/inlong/issues/12135</a>.</span></p><p></p><br>"}],"value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the\ndbName, tableName, schemaName, and username parameters. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12135 ."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-20T15:42:47.028Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/79w0cfnkhs3hctv8yn861qx3qwlc3p37"}],"source":{"discovery":"UNKNOWN"},"title":"Apache InLong: SQL Injection via String Concatenation Vulnerability Report","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-63038","datePublished":"2026-08-20T15:42:47.028Z","dateReserved":"2026-07-15T03:40:15.338Z","dateUpdated":"2026-08-20T17:09:17.259Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-20 16:17:29","lastModifiedDate":"2026-08-20 17:19:14","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63038","Ordinal":"1","Title":"Apache InLong: SQL Injection via String Concatenation Vulnerabil","CVE":"CVE-2026-63038","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63038","Ordinal":"1","NoteData":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the\ndbName, tableName, schemaName, and username parameters. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12135 .","Type":"Description","Title":"Apache InLong: SQL Injection via String Concatenation Vulnerabil"}]}}}