Skip to main content

Vendor/product archive

apache / skywalking CVEs

Beta · best-effort

4 CVEs tagged to apache / skywalking1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-30778

Published Apr 15, 2026

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54057

Published Nov 27, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are reco…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13921

Published Aug 5, 2020

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9483

Published Jun 30, 2020

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1