SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking MCP: 0.1.0.
Users are recommended to upgrade to version 0.2.0, which fixes this issue.
CVE-2026-34884
NONE
EPSS 0.24%
Updated Aug 18, 2026
Apache
CVE Details
CVE ID
CVE-2026-34884
Published Date
Aug 18, 2026
Vendor
Apache
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.24%
Likelihood of exploitation in next 30 days
Percentile:
15.0th percentile (higher than 15.0% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory