This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalThe release hardens secret manager access via a CLI parameter for MSSQL and Oracle MCP servers.
Why it matters: Secret‑manager exposure is reduced, improving security posture; severity rating of 90 indicates high impact on affected surfaces.
Summary
AI summaryUpdates 2026.07.20260713210810, chore, and healthomics across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Hardens secret manager access by making it a CLI parameter for MSSQL and Oracle MCP servers. Hardens secret manager access by making it a CLI parameter for MSSQL and Oracle MCP servers. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Medium |
Adds list‑invoice‑summaries tool to Billing Cost Management MCP server with FX, local‑currency, tax breakdowns, and PO numbers. Adds list‑invoice‑summaries tool to Billing Cost Management MCP server with FX, local‑currency, tax breakdowns, and PO numbers. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Medium |
Uses SHOW commands for metadata discovery in Redshift MCP server. Uses SHOW commands for metadata discovery in Redshift MCP server. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Updates fastmcp package to version 3.2.0. Updates fastmcp package to version 3.2.0. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Uses batchName parameter in StartRunBatch call for healthomics. Uses batchName parameter in StartRunBatch call for healthomics. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Strips SQL comments before regex evaluation to prevent bypass in Aurora‑DSQL MCP server. Strips SQL comments before regex evaluation to prevent bypass in Aurora‑DSQL MCP server. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Bugfix | Medium |
Hardens read‑only mode against session‑state mutation in Aurora‑DSQL. Hardens read‑only mode against session‑state mutation in Aurora‑DSQL. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Bugfix | Medium |
DNS‑pins spec fetches to prevent rebinding SSRF in OpenAPI MCP server. DNS‑pins spec fetches to prevent rebinding SSRF in OpenAPI MCP server. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Bugfix | Medium |
Makes managed‑policy denylist case‑insensitive in IAM MCP server. Makes managed‑policy denylist case‑insensitive in IAM MCP server. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Bugfix | Low |
Adds path validation for params_file to block sensitive file reads. Adds path validation for params_file to block sensitive file reads. Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
2026.07.20260713210810
What's Changed
- fix(healthomics): use batchName parameter in StartRunBatch call by @markjschreiber in https://github.com/awslabs/mcp/pull/4089
- fix: fastmcp package to 3.2.0 by @scottschreckengaust in https://github.com/awslabs/mcp/pull/4088
- fix(aurora-dsql-mcp-server): strip SQL comments before regex evaluation to prevent bypass by @pkale in https://github.com/awslabs/mcp/pull/4029
- chore(codeowners): add spencercorwin as codeowner for aurora-dsql-mcp… by @spencercorwin in https://github.com/awslabs/mcp/pull/4063
- docs(cloudwatch-mcp-server): remove regional availability disclaimers from PromQL tools by @gcacace in https://github.com/awslabs/mcp/pull/3999
- fix(aurora-dsql): harden read-only mode against session-state mutation by @anwesham-lab in https://github.com/awslabs/mcp/pull/4092
- fix(iam-mcp-server): make managed-policy denylist case-insensitive by @oshardik in https://github.com/awslabs/mcp/pull/4101
- feat(billing-cost-management-mcp-server): add list-invoice-summaries tool for real invoice data with FX/local-currency, tax breakdowns, and PO numbers by @malpani in https://github.com/awslabs/mcp/pull/4093
- chore: add path validation for params_file to block sensitive file reads by @jade710 in https://github.com/awslabs/mcp/pull/3807
- chore: add do not release flag temporarily by @arnewouters in https://github.com/awslabs/mcp/pull/4112
- docs: Add AWS MCP migration guide by @meghagoyal04 in https://github.com/awslabs/mcp/pull/4114
- fix(mssql-mcp-server,oracle-mcp-server): Hardening secret manager access by making it a CLI parameter by @shreyaskshekhar in https://github.com/awslabs/mcp/pull/3810
- feat(redshift-mcp-server): use SHOW commands for metadata discovery by @saeedma8 in https://github.com/awslabs/mcp/pull/4109
- fix(openapi-mcp-server): DNS-pin spec fetches to prevent rebinding SSRF by @scottschreckengaust in https://github.com/awslabs/mcp/pull/4108
- chore: release/2026.07.20260713210810 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4126
New Contributors
- @pkale made their first contribution in https://github.com/awslabs/mcp/pull/4029
- @spencercorwin made their first contribution in https://github.com/awslabs/mcp/pull/4063
- @malpani made their first contribution in https://github.com/awslabs/mcp/pull/4093
- @shreyaskshekhar made their first contribution in https://github.com/awslabs/mcp/pull/3810
- @saeedma8 made their first contribution in https://github.com/awslabs/mcp/pull/4109
Full Changelog: https://github.com/awslabs/mcp/compare/2026.07.20260706214220...2026.07.20260713210810
Security Fixes
- fix(aurora-dsql-mcp-server): strip SQL comments before regex evaluation to prevent bypass
- fix(iam-mcp-server): make managed‑policy denylist case‑insensitive
- fix(mssql-mcp-server,oracle-mcp-server): Hardening secret manager access by making it a CLI parameter
- fix(openapi-mcp-server): DNS‑pin spec fetches to prevent rebinding SSRF
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]