bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Monday, September 7, 2026
Saturday, September 5, 2026
Friday, September 4, 2026

Code Injection Vulnerability in Amazon awslabs.dynamodb-mcp-server

Amazon awslabs.dynamodb-mcp-server versions 2.0.10 through 2.1.5 contain a code injection flaw in the CDK generator component. Attackers could execute arbitrary code by crafting malicious table, index, or attribute names in data model files. If you're using affected versions, update immediately—this requires your action.

source: [aws/security-bulletin]

CVE-2026-85787: postgres-mcp-server SQL Validation Bypass – Update Required

Amazon awslabs postgres-mcp-server versions before 1.1.7 have a sneaky SQL validation bug (CVE-2026-85787) that lets attackers bypass read-only restrictions and modify data they shouldn't touch. The vulnerability lives in the SQL validation component and can be exploited through crafted SQL in user submissions. **Action required**: upgrade your postgres-mcp-server to version 1.1.7 or later immediately if you're running anything older.

source: [aws/security-bulletin]

Amazon ion-java Memory Amplification Flaw Needs Your Attention

Amazon ion-java versions below 1.12.1 have a memory-amplification denial of service vulnerability (CVE-2026-85786) triggered by highly compressed data expansion. The previous fix in 1.12.0 didn't fully patch the issue, so you'll need to upgrade immediately if you're using this Java library. This is a real threat—compressed payloads can balloon into massive memory consumption and crash your service.

source: [aws/security-bulletin]

also that day: