PT-2026-21638 · Unknown · Datalinkdc Dinky
Ana10Gy
·
Published
2026-02-24
·
Updated
2026-02-24
·
CVE-2026-3052
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DataLinkDC dinky versions up to 1.2.5
Description
A server-side request forgery condition exists in DataLinkDC dinky. The issue is located in the
proxyUba function within the dinky-admin/src/main/java/org/dinky/controller/FlinkProxyController.java file of the Flink Proxy Controller component. Manipulation of a request can lead to server-side request forgery. This issue is remotely exploitable, and details about the exploit have been publicly released. The vendor was notified but did not respond.Recommendations
Versions prior to 1.2.5 are affected. As a temporary workaround, consider disabling the
proxyUba() function until a patch is available. Restrict access to the Flink Proxy Controller module to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datalinkdc Dinky