Apache · Apache Inlong · CVE-2025-27528
**Name of the Vulnerable Software and Affected Versions**
Apache InLong versions 1.13.0 through 2.1.0
**Description**
The issue affects Apache InLong, allowing attackers to bypass its security mechanisms and enabling arbitrary file reading due to a deserialization of untrusted data vulnerability.
**Recommendations**
For Apache InLong versions 1.13.0 through 2.1.0, update to version 2.2.0 to resolve the issue. Alternatively, users can cherry-pick the solution from the provided GitHub pull request.