Apache Software Foundation Apache Skywalking vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_skywalking.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-30778P3HIGHCVSS 7.5≥ 9.7.0, ≤ 10.3.02026-04-15
CVE-2026-30778 [HIGH] CWE-202 CVE-2026-30778: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of M
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.
Users are recommended to upgrade to version 10.4.0, which fixes the issue.
nvd
CVE-2026-71216P4MEDIUMCVSS 5.3≥ 9.6.0, ≤ 11.0.02026-09-04
CVE-2026-71216 [MEDIUM] CWE-319 CVE-2026-71216: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves
PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty serves this endpoint over HTTPS and will
normally answer plain HTTP with a redirect. That does not remove the exposure.
The initial POST -- including the JSON body containing the routing key -- is
written to the socket unencrypted before any redirect response is
nvd
CVE-2025-54057P4MEDIUMCVSS 6.1≥ 10.2.0, ≤ 10.4.02025-11-27
CVE-2025-54057 [MEDIUM] CWE-80 CVE-2025-54057: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking.
This issue affects Apache SkyWalking: <= 10.2.0.
Users are recommended to upgrade to version 10.3.0, which fixes the issue.
nvd