CVE-2026-34476

CVE-2026-34476: Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

Vendor Apache Software Foundation
Product Apache SkyWalking MCP
Weakness CWE-918 · SSRF
Published April 13, 2026
Last update April 13, 2026

CVSS base score

What the vulnerability does

Description

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

Key dates

Disclosure timeline

April 13, 2026 CVE published
April 13, 2026 Record updated