{"schema_version": "1.6.1", "id": "CVE-2026-34884", "summary": "SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server", "details": "SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.\n\n\n\n\n\nThis issue affects Apache SkyWalking MCP: 0.1.0.\n\nUsers are recommended to upgrade to version 0.2.0, which fixes this issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0.1.0"}, {"last_affected": "0.1.0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/s447p6h5dfr02lx17v27phoksgb8mkkp"}]}