bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Friday, September 4, 2026

Code Injection Vulnerability in Amazon awslabs.dynamodb-mcp-server

Amazon awslabs.dynamodb-mcp-server versions 2.0.10 through 2.1.5 contain a code injection flaw in the CDK generator component. Attackers could execute arbitrary code by crafting malicious table, index, or attribute names in data model files. If you're using affected versions, update immediately—this requires your action.

source: [aws/security-bulletin]

CVE-2026-85787: postgres-mcp-server SQL Validation Bypass – Update Required

Amazon awslabs postgres-mcp-server versions before 1.1.7 have a sneaky SQL validation bug (CVE-2026-85787) that lets attackers bypass read-only restrictions and modify data they shouldn't touch. The vulnerability lives in the SQL validation component and can be exploited through crafted SQL in user submissions. **Action required**: upgrade your postgres-mcp-server to version 1.1.7 or later immediately if you're running anything older.

source: [aws/security-bulletin]

Amazon ion-java Memory Amplification Flaw Needs Your Attention

Amazon ion-java versions below 1.12.1 have a memory-amplification denial of service vulnerability (CVE-2026-85786) triggered by highly compressed data expansion. The previous fix in 1.12.0 didn't fully patch the issue, so you'll need to upgrade immediately if you're using this Java library. This is a real threat—compressed payloads can balloon into massive memory consumption and crash your service.

source: [aws/security-bulletin]

also that day:

Thursday, September 3, 2026

Amazon CodeCatalyst Blueprints SDK: OS Command Injection Vulnerability

Amazon CodeCatalyst blueprints SDK versions before 0.3.156 contain a command injection vulnerability (CVE-2026-85012) in the resynthesis framework. An attacker with repository commit access could inject shell metacharacters into the .ownership-file to execute arbitrary commands. Good news: no user action needed—AWS applies server-side validation that blocks this attack on the service side, even for older blueprint versions.

source: [aws/security-bulletin]

AWS Graviton5 Powers New EC2 Instances Across Four Fresh Regions

Amazon EC2 M9g and M9gd instances, built on the new AWS Graviton5 processors, just landed in Ireland, Singapore, Sydney, and Tokyo. These beasts deliver up to 25% better performance than Graviton4 predecessors and feature the Nitro Isolation Engine with mathematically proven security—perfect for memory-intensive workloads like databases and analytics.

source: [aws/whats-new]

also that day:

Wednesday, September 2, 2026

Amazon Ion-C Vulnerability: Update to 1.1.6 Required

Amazon Ion-C before version 1.1.6 has a nasty uncontrolled recursion bug (CVE-2026-84851) that lets attackers crash your app with specially crafted Ion data. If you're using ion-c in your stack, you need to update immediately—this is a denial-of-service vulnerability affecting all versions below 1.1.6. Remote attackers can exploit this without authentication, so don't sleep on this one.

source: [aws/security-bulletin]

Smooth Your AWS IAM Identity Center Migration with Active Directory

AWS just dropped updated guidance on migrating your identity source to IAM Identity Center, including solid strategies for moving from Active Directory and automating permission sets. If you're managing user access across multiple AWS accounts, this post walks you through the practical steps to avoid the usual migration headaches.

source: [aws/security-blog]

also that day: