CVE-2026-3052: DataLinkDC dinky Flink Proxy Controller FlinkProxyController.java proxyUba server-side request forgery
A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file dinky-admin/src/main/java/org/dinky/controller/FlinkProxyController.java of the component Flink Proxy Controller. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3052?
The severity of CVE-2026-3052 is categorized as high due to its potential for server-side request forgery attacks.
How do I fix CVE-2026-3052?
To fix CVE-2026-3052, upgrade DataLinkDC dinky to version 1.2.6 or later where the vulnerability has been addressed.
What are the potential impacts of CVE-2026-3052?
The potential impacts of CVE-2026-3052 include unauthorized access to internal resources and data leakage.
Which versions of DataLinkDC dinky are affected by CVE-2026-3052?
CVE-2026-3052 affects DataLinkDC dinky versions up to and including 1.2.5.
Is CVE-2026-3052 a client-side or server-side vulnerability?
CVE-2026-3052 is a server-side vulnerability affecting the FlinkProxyController's handling of requests.