MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

CVE record published for the Apache SkyWalking MCP SSRF and GraphQL injection fixed in April

CVE-2026-34884 reached the CVE list on 2026-08-18 for an SSRF through the set_skywalking_url tool and a GraphQL expression injection in Apache SkyWalking MCP 0.1.0. Version 0.2.0 fixed it on 2026-04-02 and Apache announced it to its mailing list on 2026-04-13 rating it "important". NVD scores the record 9.8 critical; the Apache record carries no CVSS at all.

CVE-2026-34884 was published on 2026-08-18 against Apache SkyWalking MCP 0.1.0, recording a server-side request forgery through the set_skywalking_url tool together with a GraphQL expression injection. The Apache Software Foundation is the assigning authority, so the record is the project's own text.

The fix long predates the record. Version 0.2.0, which the record names as the remedy, was released on 2026-04-02, and Apache announced the issue to its mailing list on 2026-04-13. Nineteen weeks then passed before the CVE record appeared. The mailing-list announcement and the CVE record carry the same description and the same credit to Andrea Cosentino as reporter.

The two surfaces disagree about how serious it is, and the disagreement is worth stating rather than resolving. Apache's announcement rates the issue "important", which is the second tier of its own four-level scale, and neither the announcement nor the CNA record asserts a CVSS score. The NVD entry, still marked "Awaiting Analysis" when retrieved on 2026-08-20, carries a CVSS 3.1 base score of 9.8 critical. A reader who meets this issue through a vulnerability feed will most likely see the 9.8 and not the project's own rating.

The affected version is the server's first release. MCP News verified this server on 2026-08-18 and published a story on 2026-08-14 about its migration to the official Go SDK, work that landed on the default branch well after 0.2.0 and is not covered by any tagged release.

Related servers and clients

Related publishers

How was this verified, and what are the sources?

Published · last verified · confidence 1.00.

  1. CVE-2026-34884 CNA record, assigner apache, datePublished 2026-08-18T07:26:38Z, dateUpdated 2026-08-19T13:28:04Z - title "Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server"; affects Apache SkyWalking MCP 0.1.0; "Users are recommended to upgrade to version 0.2.0, which fixes this issue"; credits Andrea Cosentino as reporter; the record carries no CVSS metrics and its sole reference is the Apache mailing-list thread - accessed
  2. Apache announcement thread posted by Qiuxia Fan at 2026-04-13T12:55:11Z - gives "Severity: important", affected versions "Apache SkyWalking MCP 0.1.0", the same SSRF and GraphQL expression injection description, the 0.2.0 upgrade recommendation, and Andrea Cosentino as reporter; no CVSS score is stated - accessed
  3. apache/skywalking-mcp releases - v0.2.0 published 2026-04-02, v0.1.0 published 2026-03-23, placing the fix eleven days before the Apache announcement and nineteen weeks before the CVE record - accessed
  4. NVD record for CVE-2026-34884, retrieved 2026-08-20 with vulnStatus "Awaiting Analysis" - carries CVSS 3.1 base score 9.8 CRITICAL, which the Apache CNA record does not assert - accessed

← All news