PT-2026-21638 · Unknown · Datalinkdc Dinky

Ana10Gy

·

Published

2026-02-24

·

Updated

2026-02-24

·

CVE-2026-3052

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DataLinkDC dinky versions up to 1.2.5
Description A server-side request forgery condition exists in DataLinkDC dinky. The issue is located in the proxyUba function within the dinky-admin/src/main/java/org/dinky/controller/FlinkProxyController.java file of the Flink Proxy Controller component. Manipulation of a request can lead to server-side request forgery. This issue is remotely exploitable, and details about the exploit have been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 1.2.5 are affected. As a temporary workaround, consider disabling the proxyUba() function until a patch is available. Restrict access to the Flink Proxy Controller module to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3052

Affected Products

Datalinkdc Dinky