HTTP Plaintext Transmission Vulnerability in PagerDuty Integration Key
CVE-2026-71216
Currently unrated
What is CVE-2026-71216?
The PagerDuty alarm hook exposes a significant security weakness by transmitting the integration routing key over unencrypted HTTP. When users interact with this endpoint, the initial POST request, which contains sensitive information in the JSON body, is sent without encryption before a redirect to HTTPS occurs. Although subsequent requests might be secured, the initial data leak compromises the integration key's confidentiality. Users are urged to upgrade to Apache SkyWalking version 11.0.0 to rectify this security issue and protect their data.
Affected Version(s)
Apache SkyWalking 9.6.0 <= 11.0.0