What is CVE-2026-34884?
CVE-2026-34884 is a critical vulnerability in Apache SkyWalking MCP that allows SSRF (Server-Side Request Forgery) via the set_skywalking_url tool and GraphQL expression injection. This issue affects version 0.1.0, and users are strongly advised to upgrade to version 0.2.0 immediately.
Azərbaycanca: CVE-2026-34884 Apache SkyWalking MCP-də aşkar edilmiş kritik zəiflikdir. Bu boşluq SSRF (Server-Side Request Forgery) hücumuna və GraphQL expression injection-a imkan verir. İstifadəçilər dərhal 0.2.0 versiyasına yüksəlməlidir.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Apache
FAQ1
Which product is affected by CVE-2026-34884 and how is it exploited?
This critical vulnerability affects version 0.1.0 of Apache SkyWalking MCP. It allows SSRF (Server-Side Request Forgery) via the set_skywalking_url tool and GraphQL expression injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.