CVE 6.3 MEDIUM

Pinpoint – Server-Side Request Forgery via Alarm Webhook Registration_CVE-2026-57947

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N

Description

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.

Basic Information

ID CVE-2026-57947
Source VulnCheck
Published Jun 29, 2026 at 17:18

Affected Product

Vendor pinpoint-apm
Product pinpoint
Affected Versions pinpoint-apm pinpoint 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.