HTTP Plaintext Transmission Vulnerability in PagerDuty Integration Key
CVE-2026-71216

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-71216?

The PagerDuty alarm hook exposes a significant security weakness by transmitting the integration routing key over unencrypted HTTP. When users interact with this endpoint, the initial POST request, which contains sensitive information in the JSON body, is sent without encryption before a redirect to HTTPS occurs. Although subsequent requests might be secured, the initial data leak compromises the integration key's confidentiality. Users are urged to upgrade to Apache SkyWalking version 11.0.0 to rectify this security issue and protect their data.

Affected Version(s)

Apache SkyWalking 9.6.0 <= 11.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ambesh.infosec@gmail.com
.