{
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
      },
      "title": "Authenticated SSRF via POST /api/node/testConnection",
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "CWE-918 Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "cweId": "CWE-918",
              "type": "CWE"
            }
          ]
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "affected": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache InLong",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.4.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ],
      "descriptions": [
        {
          "value": "Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.\u00a0\u00a0Any authenticated\u00a0user (no admin role required) can cause the\u00a0InLong Manager server to make outbound HTTP requests or TCP connections to\narbitrary internal hosts and ports.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]\u00a0 https://github.com/apache/inlong/pull/12130 .",
          "lang": "en",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">&nbsp;Any </span><span style=\"background-color: rgb(255, 255, 255);\">authenticated</span><span style=\"background-color: rgb(255, 255, 255);\">&nbsp;user (no admin role required) can cause the&nbsp;</span><span style=\"background-color: rgb(255, 255, 255);\">InLong Manager server to make outbound HTTP requests or TCP connections to</span><br><span style=\"background-color: rgb(255, 255, 255);\">arbitrary internal hosts and ports.</span></p><p>This issue affects Apache InLong: from 2.0.0 before 2.4.0.</p><p></p><p><span style=\"background-color: var(--wht);\">Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.</span></p><p><span style=\"background-color: rgb(255, 255, 255);\">[1]&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/apache/inlong/pull/12130\">https://github.com/apache/inlong/pull/12130</a>.</span></p><p></p>"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://lists.apache.org/thread/b3rtzssd8hdk0dyq4y6mpdx6jj5ro4g6",
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "other": {
            "type": "Textual description of severity",
            "content": {
              "text": "important"
            }
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Geo",
          "type": "finder"
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "cveId": "CVE-2026-63044",
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "serial": 1,
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}