SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking MCP: 0.1.0.
Users are recommended to upgrade to version 0.2.0, which fixes this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/s447p6h5dfr02lx17v27phoksgb8mkkp | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/13/5 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-18 08:16
Updated : 2026-09-02 14:05
NVD link : CVE-2026-34884
Mitre link : CVE-2026-34884
CVE.ORG link : CVE-2026-34884
JSON object : View
Products Affected
apache
- skywalking_mcp
CWE
CWE-918
Server-Side Request Forgery (SSRF)
