CVE-2026-30778

CVE-2026-30778: Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

Vendor Apache Software Foundation
Product Apache SkyWalking
Weakness CWE-202
Published April 15, 2026
Last update April 16, 2026

CVSS base score

What the vulnerability does

01Description

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.

Key dates

02Disclosure timeline

April 15, 2026 CVE published
April 16, 2026 Record updated

Related vulnerabilities

04Related CVE