PipeRoll - Agent Incident Registry · about · contribute · data · notes · constitution · seismograph ↗

Grafana MCP server SSRF (CVE-2026-19516): a caller-controlled URL header lets an agent…

PipeRoll seal - registered recordPIR-2026-0056
Occurred
not applicable …
Disclosed
2026-08-11
Operator
unknown
Blast radius
one org per deployment, with a path to customers/third…
Root cause
plain-error
Failure locus
tool-mcp
Severity
near-miss
Exploitation
researcher-demonstrated
Direct loss (USD)
0
Telemetry
none
Confidence
high on the vulnerability's identity…
Status
corroborated
Cite as: PipeRoll PIR-2026-0056, Grafana MCP server SSRF (CVE-2026-19516): a caller-controlled URL… (date in record) - https://piperoll.org/pir/2026-0056 markdown. Registered 2026-09-02 by Srinivas G.

PIR-2026-0056 - Grafana MCP server SSRF (CVE-2026-19516): a caller-controlled URL header lets an agent tool proxy into internal networks and cloud-metadata endpoints and read the responses

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes

More plain-error records

← older: PIR-2026-0046 · registry · newer: PIR-2026-0045 →