SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-34884

CRITICAL · CVSS 9.8 EPSS 0.68%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache SkyWalking MCP version 0.1.0 is vulnerable to a Server-Side Request Forgery (SSRF) and GraphQL expression injection, which could allow an attacker to manipulate requests and potentially access sensitive internal resources. Organizations using this version should prioritize upgrading to 0.2.0 to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-34884
Severity
CRITICAL
CVSS
9.8
EPSS
0.68%
Apache

Original NVD Description

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)