Server-Side Request Forgery (SSRF) in Apache InLong - CVE-2026-63044
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper control of outbound network requests in POST /api/node/testConnection when handling user-supplied connection test requests. A remote user can send a specially crafted request to perform server-side request forgery.
No administrative role is required for exploitation.