Skip to content
AWSAWS-2026-070

Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt...

UnratedCVE-2026-18655 · Published Aug 3, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions:   Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions:   Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument before it executes, and can reject calls with hostnames that do not match the expected Amazon MQ endpoint pattern (e.g., .mq. .on.aws). References: CVE-2026-18655 GHSA-xwj6-8x5h-hjp6 Acknowledgement: We would like to thank Marios Gyftos for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-070-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions:   Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument before it executes, and can reject calls with hostnames that do not match the expected Amazon MQ endpoint pattern (e.g., .mq. .on.aws). References: CVE-2026-18655 GHSA-xwj6-8x5h-hjp6 A

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.