cvesecurityvulnerability
CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header
CVE-2026-19516 is a server-side request forgery in the Grafana MCP Server. A caller can set the X-Grafana-URL header to any destination and use the grafana_api_request tool to reach internal services and cloud metadata endpoints. Fixed in mcp-grafana 1.1.0 and later.