Server-Side Request Forgery in Pinpoint by Alibaba Cloud
CVE-2026-57947

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 June 2026

What is CVE-2026-57947?

The Pinpoint product from Alibaba Cloud contains a vulnerability within its webhook registration endpoint that is susceptible to server-side request forgery. This flaw allows authenticated users to register internal URLs because of a lack of adequate SSRF protections. Malicious actors could exploit this weakness to artificially trigger alarm thresholds, compelling the server to send POST requests to internal hosts or sensitive metadata endpoints. Such access may lead to unauthorized exposure of internal network resources, posing a significant risk to data integrity and confidentiality.

Affected Version(s)

pinpoint 0 <= 3.1.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.