CVE-2026-14471: Aws Mcp Gateway & Registry

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later.

Affected products

  • Aws Mcp Gateway & Registry: from 1.0.3, up to and including 1.0.12

Published 2026-07-06. Last modified 2026-07-07.