CVE-2026-57947
HIGHPinpoint - Server-Side Request Forgery via Alarm Webhook Registration
Title source: cnaDescription
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.
References (2)
Core 2
Core References
Issue Tracking issue-tracking
Researcher Disclosure
https://github.com/pinpoint-apm/pinpoint/issues/13857
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/pinpoint-server-side-request-forgery-via-alarm-webhook-registration
Scores
CVSS v3
8.5
EPSS
0.0024
EPSS Percentile
15.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
pinpoint-apm/pinpoint
< 3.1.0
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026