Server-Side Request Forgery in Pinpoint by Alibaba Cloud
CVE-2026-57947
6.3MEDIUM
What is CVE-2026-57947?
The Pinpoint product from Alibaba Cloud contains a vulnerability within its webhook registration endpoint that is susceptible to server-side request forgery. This flaw allows authenticated users to register internal URLs because of a lack of adequate SSRF protections. Malicious actors could exploit this weakness to artificially trigger alarm thresholds, compelling the server to send POST requests to internal hosts or sensitive metadata endpoints. Such access may lead to unauthorized exposure of internal network resources, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
pinpoint 0 <= 3.1.0
