Known Vulnerabilities for Amazon-mq-mcp-server by AWS
Listed below are 9 of the newest known vulnerabilities associated with "Amazon-mq-mcp-server" by "AWS".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61448 json | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-18954 json | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow a... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-18953 json | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-serv... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-18655 json | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazo... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18245 json | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated ... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-16756 json | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Ama... | Not Provided | 2026-07-23 | 2026-08-12 |
| CVE-2026-15957 json | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface defin... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-13762 json | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass ... | Not Provided | 2026-06-29 | 2026-06-29 |
| CVE-2024-53095 json | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. R... | Not Provided | 2024-11-21 | 2026-08-04 |