Cleartext transmission of sensitive information in Apache SkyWalking - CVE-2026-71216
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose the PagerDuty integration routing key.
The vulnerability exists due to cleartext transmission of sensitive information in the PagerDuty alarm hook when sending alarm notifications over HTTP. A remote attacker can intercept the unencrypted initial POST request to disclose the PagerDuty integration routing key.
The initial POST is transmitted before an HTTP redirect response is received.