Skip to content
AWSAWS-2026-054

AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL

UnratedCVE-2026-15643 · Published Jul 14, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643 a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Impacted versions:   Resolution: This issue has been addressed in awslabs.healthlake-mcp-server version 0.0.14 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: In the interim, scope the IAM policy used by the server to least privilege rather than Resource: "*", and do not rely on the --readonly flag ...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643 a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Impacted versions:   Resolution: This issue has been addressed in awslabs.healthlake-mcp-server version 0.0.14 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: In the interim, scope the IAM policy used by the server to least privilege rather than Resource: "*", and do not rely on the --readonly flag as a security boundary — it is an in-process guard over the mutating tools, not an IAM control, so disclosed credentials retain their full granted authority. Operators using role-based (STS) deployments should consider rotating the affected role's credentials if they suspect using an affected version. References: CVE-2026-15643 GHSA-c5vr-x62j-w6rw Acknowledgement: We would like to thank Marios Gyftos for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-054-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643 a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Impacted versions:   Resolution: This issue has been addressed in awslabs.healthlake-mcp-server version 0.0.14 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: In the interim, scope the IAM policy used by the server to least privilege rather than Resource: "*", and do not rely on the --readonly flag as a security boundary — it is an in-process guard over

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Path traversal and arbitrary file write in the workflow linters of...
UnratedJul 17
Issue with Athena Federated Query Synapse Connector
UnratedJul 17
Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
UnratedJul 16
OS command injection in jsii-diff in AWS jsii
UnratedJul 15
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
UnratedJul 15
aws-load-balancer-controller: insufficient isolation
Medium5.8Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.