Amazon Amazon Amazon

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Amazon product.

RSS Feeds for Amazon security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Amazon products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Amazon Sorted by Most Security Vulnerabilities since 2018

Amazon Aws233 vulnerabilities

Amazon Freertos20 vulnerabilities

Amazon Tough5 vulnerabilities

Amazon Workspaces4 vulnerabilities

Amazon Aws Encryption Sdk2 vulnerabilities

Amazon Strands Agents Tools2 vulnerabilities

Amazon Ssm Agent2 vulnerabilities

Amazon Ion Java1 vulnerability

Amazon Freertos Plus Tcp1 vulnerability

Amazon Ion1 vulnerability

Amazon Ion C1 vulnerability

Amazon S2n Tls1 vulnerability

Amazon Kiro Cli1 vulnerability

Amazon Kiro Ide1 vulnerability

Amazon Linux 20231 vulnerability

Amazon Opensearch Service1 vulnerability

Amazon Amplify Cli1 vulnerability

Amazon Deep Java Library1 vulnerability

Amazon Alexa1 vulnerability

Recent Amazon Security Advisories

Advisory Title Published
2026-09-11 CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026
2026-09-11 CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2 September 11, 2026
2026-09-11 CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin September 11, 2026
2026-09-11 CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection September 11, 2026
2026-09-10 CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent September 10, 2026
2026-09-10 CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library September 10, 2026
2026-09-09 CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server September 9, 2026
2026-09-09 CVE-2026-87911 September 9, 2026
2026-09-09 CVE-2026-85788 - Issue with awslabs mysql-mcp-server September 9, 2026
2026-09-08 CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards September 8, 2026

By the Year

In 2026 there have been 139 vulnerabilities in Amazon with an average score of 7.4 out of ten. Last year, in 2025 Amazon had 46 security vulnerabilities published. That is, 93 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.72.




Year Vulnerabilities Average Score
2026 139 7.40
2025 46 6.68
2024 26 6.96
2023 23 6.74
2022 23 7.27
2021 17 8.64
2020 8 6.94
2019 6 6.83
2018 19 6.76

It may take a day or so for new Amazon vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-89332 Sep 11, 2026
Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.
Aws
CVE-2026-89090 Sep 11, 2026
Unrecovered Panic in AWS SDK-Go v2 Header Decoder An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Aws
CVE-2026-18061 Sep 11, 2026
XXE in AWS Advanced JDBC Wrapper 3.3.04.2.0 RemoteQueryCachePlugin Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value. To remediate this issue, users should upgrade to version 4.3.0 or later.
Aws
CVE-2026-89066 Sep 11, 2026
projen <0.103.0 Task Injection via Shell Metacharacters Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Aws
CVE-2026-89065 Sep 11, 2026
Relative path traversal in projen <0.101.37: recursive file deletion Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this issue, users should upgrade to version 0.101.37. The corrected containment check is automatically applied by the projen runtime next time you run it.
Aws
CVE-2026-89049 Sep 10, 2026
Amazon SSM Agent SSRF via Port Forwarding (3.3.4850) A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Aws
CVE-2026-85228 Sep 10, 2026
Amazon DJL 0.13-0.36 Integer Overflow in Tensor Buffer Validation An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.
Deep Java Library
Aws
CVE-2026-87913 Sep 10, 2026
AWS Security Agent MCP before 0.2.0 S3 Ownership Verification Flaw A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Aws
CVE-2026-87912 Sep 10, 2026
Missing S3 Bucket Ownership Verification in AWS Security Agent Plugin before 1.1.0 A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Aws
CVE-2026-87911 Sep 09, 2026
OS Command Injection in Amazon awslabs Postgres-MCP-Server 1.1.6 Read-Only Mode An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.
Aws
CVE-2026-85788 Sep 09, 2026
Amazon awslabs mysql-mcp-server 1.0.23: SQL Detector Bypass via Inline Comments Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.
Aws
CVE-2026-84942 Sep 08, 2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
Aws
CVE-2026-85787 Sep 04, 2026
Amazon Postgres-MCP-Server SQL Injection 1.1.6 An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. To remediate this issue, users should upgrade to version 1.1.7 or above.
Postgres Mcp Server
Aws
CVE-2026-85786 Sep 04, 2026
Amazon ion-java < 1.12.1: GZIP Decompression DoS via Unchecked Compression Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.
Ion Java
Aws
CVE-2026-85781 Sep 04, 2026
Recursive dir deletion via crafted PV volumeHandle in EFS CSI Driver <v3.4.1 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1.
Aws
CVE-2026-85656 Sep 04, 2026
Amazon Linux log4j-cve-2021-44228-hotpatch OS Command Injection before 1.3-9 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Aws
Log4j Cve 2021 44228 Hotpatch
CVE-2026-85654 Sep 04, 2026
Amazon DynamoDB MCP Server <2.1.6: TL Template Exploit Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.
Awslabs Dynamodb Mcp Server
Aws
CVE-2026-85028 Sep 03, 2026
AWS FPGA Dev Kit 2.3.4 Temp File Priv Esc via Installation Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.
Aws
CVE-2026-85012 Sep 03, 2026
AWS CodeCatalyst Blueprint Resynthesis OS Command Injection (CWE-78) <0.3.156 Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.
Aws
CVE-2026-84851 Sep 02, 2026
Amazon Ion-C <1.1.6 Uncontrolled Recursion DoS via Crafted Ion Data An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
Aws
Ion C
CVE-2026-83551 Sep 01, 2026
Amazon SageMaker SDK v3.11.0/v2.256.0: HMAC Leak @step/@remote Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.
Aws
CVE-2026-83497 Aug 31, 2026
OpenSearch SQL Cursor Pagination Unrestricted Deserialization RCE Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Amazon Opensearch Service
Aws
CVE-2026-81849 Aug 28, 2026
Path Traversal in aws:downloadContent of amazon-ssm-agent <3.3.4515.0 Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is directed to retrieve. This issue may lead to arbitrary code execution as root if specific sensitive files are overwritten. To remediate this issue, customers should upgrade amazon-ssm-agent to version 3.3.4515.0 or later.
Amazon Ssm Agent
Aws
CVE-2026-81838 Aug 27, 2026
Path Traversal in awsdac 0.10-0.23 Zip Extraction A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should upgrade to the version 0.24 or later.
Aws
CVE-2026-78379 Aug 25, 2026
Amazon Strands Agents Tools 0.8.4 LLM Prompting RCE via python_repl Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0.8.5 or later.
Strands Agents Tools
Aws
CVE-2026-77811 Aug 21, 2026
OpenSearch Dashboards XSS via dashboardsobservability plugin Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web content.
Aws
CVE-2026-77810 Aug 21, 2026
Neptune Connector Unauthorized Access via Athena Federated Query pre-2026.30.1 In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Aws
CVE-2026-77237 Aug 21, 2026
FreeRTOS-Kernel <11.3.1 QueueSet Access Validation Bug Unlocks Privileged Memory Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.
Aws
CVE-2026-77236 Aug 21, 2026
FreeRTOSKernel 11.3.0: Heap Metadata OOB via Undersized Stack Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later.
Aws
CVE-2026-77235 Aug 21, 2026
UAF via Missing Priv Verif in Secure Context Clean FreeRTOS-Kernel <11.3.1 Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.
Aws
CVE-2026-77234 Aug 21, 2026
FreeRTOS Kernel <11.3.1 Improper Input Validation Enables Privileged Execution Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
Aws
CVE-2026-18420 Aug 20, 2026
OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution) Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Aws
CVE-2026-75910 Aug 20, 2026
Amazon Athena Query ClickHouse Connector v2026.17.1 Priv Escalation Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.
Aws
CVE-2026-75936 Aug 18, 2026
DoS via GZIP auto-decompress in Amazon ion-java <1.12.0 Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.
Aws
CVE-2026-75935 Aug 18, 2026
Amazon ion-java 1.12 Uncontrolled Heap Prealloc via ion stream cursor Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.
Aws
CVE-2026-75897 Aug 18, 2026
OpenSearch Dashboards Capabilities Route Unbounded Payload DOS Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
Aws
CVE-2026-18428 Aug 13, 2026
OpenSearch SQL Plugin Flint SQL Bypass Allows Arbitrary Code Execution on Spark A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
Aws
CVE-2026-19643 Aug 12, 2026
aws-sdk-c++ OOB Read: Base64 Decoder <1.11.862 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Aws
CVE-2026-19642 Aug 12, 2026
OOB Write in aws-sdk-cpp Base64 Decoder before 1.11.862 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Aws
CVE-2026-18952 Aug 12, 2026
OpenSearch SecurityAnalytics Plugin SSRF via Unvalidated Threat Intel Feed URL Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Aws
CVE-2026-19311 Aug 12, 2026
Missing Auth in OpenSearch Execute Monitor API Enables Data Manipulation Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Aws
CVE-2026-19111 Aug 06, 2026
Insecure DOOR in Amazon Strands Agent Tools <0.8.3 (memory tools) Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3.
Aws
CVE-2026-18954 Aug 05, 2026
Amazon AWS Labs DocumentDB MCP Server 1.0.11 Aggregation Pipeline Auth Bypass Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later.
Aws
CVE-2026-18953 Aug 05, 2026
Amazon awslabs.aws-transform-mcp-server 0.1.0-0.1.4 Pathname Traversal via savePath Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later.
Aws
CVE-2026-18657 Aug 04, 2026
Kiro CLI before 2.10.0 Uncontrolled Search Path Exec An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory. To remediate this issue, users should upgrade to version 2.10.0 or higher.
Kiro Cli
Aws
CVE-2026-18656 Aug 04, 2026
Kiro IDE Uncontrolled Search Path (1.0.227) Windows An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 1.0.228 or higher.
Kiro Ide
Aws
CVE-2026-18830 Aug 04, 2026
Bedrock AgentCore Flaw Lets Authenticated Remote Users Execute Tools Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
Aws
CVE-2026-18733 Aug 03, 2026
Prompt Injection in Amazon Strands Agents Tools <0.8.0 Allows Remote OS Cmd Exec A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.
Aws
CVE-2026-18654 Aug 03, 2026
MITM in AWS CLI v1/<1.45.28 & v2/<2.35.3: EMR SSH Helper key exchange w/o auth Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.
Aws
CVE-2026-18655 Aug 03, 2026
Amazon MQ MCP Server RabbitMQ Connector Endpoint Bypass <=2.0.24 Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. To remediate this issue, users should upgrade to version 2.0.24.
Aws
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.