Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1]
https://github.com/apache/inlong/pull/11732
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27522.json"
[
{
"signature_version": "v1",
"source": "https://github.com/apache/inlong/commit/86c893cfd8f7ba9ffce5d20abef6cd360f502fdf",
"target": {
"function": "testFilterSensitive",
"file": "inlong-manager/manager-pojo/src/test/java/org/apache/inlong/manager/pojo/sink/mysql/MySQLSinkDTOTest.java"
},
"deprecated": false,
"digest": {
"function_hash": "330014795989017731365637553568299329638",
"length": 3879.0
},
"signature_type": "Function",
"id": "CVE-2025-27522-406e9789"
},
{
"signature_version": "v1",
"source": "https://github.com/apache/inlong/commit/86c893cfd8f7ba9ffce5d20abef6cd360f502fdf",
"target": {
"function": "containSensitiveKey",
"file": "inlong-manager/manager-pojo/src/main/java/org/apache/inlong/manager/pojo/util/MySQLSensitiveUrlUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "30016277004068194237363209504638187085",
"length": 261.0
},
"signature_type": "Function",
"id": "CVE-2025-27522-6dc468c4"
},
{
"signature_version": "v1",
"source": "https://github.com/apache/inlong/commit/86c893cfd8f7ba9ffce5d20abef6cd360f502fdf",
"target": {
"file": "inlong-manager/manager-pojo/src/main/java/org/apache/inlong/manager/pojo/util/MySQLSensitiveUrlUtils.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"291919796634205278697421361823279634749",
"234197014509822500510772843144597538218",
"51459997764898905614588498081541463717",
"112293563504342978121554883362513854444",
"147297442087133441183406575786486541767"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2025-27522-a3958aa6"
},
{
"signature_version": "v1",
"source": "https://github.com/apache/inlong/commit/86c893cfd8f7ba9ffce5d20abef6cd360f502fdf",
"target": {
"file": "inlong-manager/manager-pojo/src/test/java/org/apache/inlong/manager/pojo/sink/mysql/MySQLSinkDTOTest.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"86224597110922167188246913039204399049",
"319402781962628971720666493684364606673",
"88261001503546872201920635454675786912",
"205417793798771382010058175276350497008"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2025-27522-b0217815"
}
]
[
{
"events": [
{
"introduced": "1.13.0"
},
{
"fixed": "2.2.0"
}
]
},
{
"events": [
{
"introduced": "1.13.0"
},
{
"last_affected": "2.1.0."
}
]
}
]
"2026-04-12T15:36:23Z"