bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: RabbitMQ

show all
Monday, August 3, 2026

AWS Amazon MQ MCP Server: Critical Credential Leak via Prompt Injection

AWS Amazon MQ MCP Server versions up to 2.0.23 have a nasty vulnerability (CVE-2026-18655) that lets attackers snag your broker credentials and OAuth tokens through prompt injection. The flaw affects RabbitMQ connection tools—basically, a crafted endpoint can trick the system into leaking sensitive auth data. You need to upgrade to version 2.0.24 or later immediately. This one's serious and requires immediate action.

> source: aws.amazon.com