This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.
Users are recommended to upgrade to version 10.4.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-27h3-crw2-q36w | SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information |
Mon, 20 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:skywalking:*:*:*:*:*:*:*:* |
Thu, 16 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache skywalking |
|
| Vendors & Products |
Apache
Apache skywalking |
Wed, 15 Apr 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue. | |
| Title | Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. | |
| Weaknesses | CWE-202 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-16T12:05:25.254Z
Reserved: 2026-03-05T01:06:13.446Z
Link: CVE-2026-30778
Updated: 2026-04-15T11:25:13.874Z
Status : Analyzed
Published: 2026-04-15T11:16:33.603
Modified: 2026-04-20T16:46:52.490
Link: CVE-2026-30778
No data.
OpenCVE Enrichment
Updated: 2026-04-17T07:00:08Z
Github GHSA