aws
Latest CVEs
The 15 most recently published vulnerabilities affecting aws.
- CVE-2026-19111Insecure direct object reference in Strands Agents Tools memory tool namespace isolation8.1
- CVE-2026-18954Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server5.5
- CVE-2026-18953Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server8.6
- CVE-2026-18830Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API8.1
- CVE-2026-18733Prompt injection bypasses shell tool consent gate in Strands Agents Tools8.8
- CVE-2026-18654Disabled SSH host key verification in Amazon AWS CLI EMR helper commands6.8
- CVE-2026-18655Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection6.5
- CVE-2026-18394Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration7.4
- CVE-2026-18481Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft7.3
- CVE-2026-18140Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers7.5
- CVE-2026-18245Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react9.0
- CVE-2026-16796Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()7.3
- CVE-2026-16756Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service7.5
- CVE-2026-16584AWS API MCP Server Security Policy Bypass via Startup Failure7.0
- CVE-2026-16317Silent Drop of TLS 1.3 Encrypted Records in s2n-tls6.5