https://seclists.org/oss-sec/2026/q3/647: CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP

Published Sep 4, 2026
·
Updated

Affected Software

1 affected component
Apache SkyWalking>=9.6.0<=11.0.0

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments running Apache SkyWalking versions 9.6.0 through 11.0.0 that use the PagerDuty alarm hook are exposed when that hook sends requests over HTTP. An observer able to capture traffic between SkyWalking and the PagerDuty endpoint could obtain the integration routing key from the initial request.

2

Does PagerDuty's HTTP-to-HTTPS redirect protect the routing key?

No. The initial HTTP POST, including its JSON body containing the routing key, is sent unencrypted before PagerDuty returns a redirect response. A later retry over HTTPS does not protect the first transmission.

3

What should teams do to remediate this?

The advisory recommends upgrading to Apache SkyWalking 11.0.0, which it identifies as fixing the issue. The affected-version range also lists versions through 11.0.0, so teams should verify the vendor's current release guidance when planning the upgrade.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203