Server-Side Request Forgery Vulnerability in Apache SkyWalking MCP
CVE-2026-34476
7.1HIGH
What is CVE-2026-34476?
A server-side request forgery (SSRF) vulnerability exists in Apache SkyWalking MCP, specifically affecting version 0.1.0. This issue could potentially allow an attacker to craft malicious requests through the SW-URL header, which can lead to unauthorized access to internal services. It is crucial for users to upgrade to version 0.2.0, which addresses and mitigates this vulnerability.
Affected Version(s)
Apache SkyWalking MCP 0.1.0