<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T22:14:05.605724+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-16584</id>
    <title>CVE-2026-16584 — AWS API MCP Server Security Policy Bypass via Startup Failure</title>
    <updated>2026-10-08T22:14:05.607709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> aws-api-mcp-server</p>
<p>Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected.</p>
<p>To remediate this issue, users should upgrade to version 1.3.47.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-16584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29w2-fq35-v728</id>
    <title>GHSA-29w2-fq35-v728 — AWS API MCP Server Security Policy Bypass via Startup Initialization Failure</title>
    <updated>2026-10-08T22:14:05.607774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: awslabs.aws-api-mcp-server</p>
<p>## Summary
The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. An issue exists where, if the data used to enforce this policy fails to initialize at server startup, the per-request policy check is silently skipped for the lifetime of the process.</p>
<p>### Impact
On startup, the server loads data used to enforce the configured security policy. If that load fails, the server continues running without the enforcement data in place. In the default configuration, the per-request security check is then bypassed for the lifetime of the process: configured deny and gate rules are not consulted, and AWS API operations the policy was intended to restrict execute without enforcement. The scope is limited to the security-policy gate; IAM permissions on the configured credentials remain in effect and continue to bound what the server can do.</p>
<p>**Impacted versions**: &gt;= 0.2.13 AND &lt; 1.3.47</p>
<p>### Patches
This issue has been addressed in awslabs.aws-api-mcp-server version 1.3.47. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.</p>
<p>### Workarounds
Any one of the following prevents the bypa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29w2-fq35-v728"/>
  </entry>
</feed>
