
Apache SkyWalking CVE-2025-54057: Stored XSS https://www.openwall.com/lists/oss-security/2026/04/13/3 CVE-2026-34476: SSRF via SW-URL Header in MCP Server https://www.openwall.com/lists/oss-security/2026/04/13/4 CVE-2026-34884: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server https://www.openwall.com/lists/oss-security/2026/04/13/5
Post summary
The message announces three new CVEs affecting Apache SkyWalking—one a stored XSS and two SSRF/GraphQL injection flaws—providing concise technical descriptors for each.


