OVERVIEW CVE-2026-34476 is a Server-Side Request Forgery (SSRF) vulnerability in Apache SkyWalking MCP version 0.1.0, exploitable through the SW-URL header. This flaw allows an attacker to manipulate the application into making unintended requests to internal or external systems, potentially exposing sensitive resources. SEVERITY The vulnerability carries a HIGH CVSS score of 7.1, with a network-based attack vector requiring low complexity and low privileges to exploit. The attack does not require user interaction and could result in high confidentiality impact and low integrity impact, though availability remains unaffected. The EPSS score of 0.00079 indicates this is not yet a widespread target in the wild. EXPLOITATION STATUS There is currently no evidence of active exploitation or public exploit code availability. The vulnerability is marked as inactive on threat intelligence lists and does not appear in known exploitation tracking databases. However, users running version 0.1.0 should prioritize upgrading to version 0.2.0 to remediate this risk before potential weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 0.2.0CPE matchmatch criteria | cpe:2.3:a:apache:skywalking_mcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.