This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 4d
MCP SaaS Integrations
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
aws
mcp
mcp-client
mcp-clients
mcp-host
mcp-server
+3 more
mcp-servers
mcp-tools
modelcontextprotocol
Affected surfaces
auth
Summary
AI summaryBroad release touches 2026.07.20260722140608, aws-api-mcp-server, eks-mcp-server, and deps.
Full changelog
2026.07.20260722140608
What's Changed
- chore(aws-api-mcp-server): upgrade AWS CLI to v1.45.47 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4128
- feat(docusaurus): add Japanese (ja) locale for the documentation site by @watilde in https://github.com/awslabs/mcp/pull/4106
- docs(aws-api-mcp): update README.md by @arnewouters in https://github.com/awslabs/mcp/pull/4129
- chore(aws-api-mcp-server): upgrade AWS CLI to v1.45.48 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4133
- fix(openapi-mcp-server): block external $ref SSRF/LFI in spec parsing by @prajwalendra in https://github.com/awslabs/mcp/pull/4141
- chore(deps): group Dependabot updates across directories to stop the per-directory PR explosion by @scottschreckengaust in https://github.com/awslabs/mcp/pull/4267
- fix(redshift-mcp-server): graceful cluster discovery when IAM lacks serverless or provisioned access by @S-gunasekhar in https://github.com/awslabs/mcp/pull/3518
- chore(aws-api-mcp-server): upgrade AWS CLI to v1.45.50 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4272
- feat: add search_table tool for large table filtering by @alexisareyn in https://github.com/awslabs/mcp/pull/3642
- fix(aws-iac-mcp-server): validate rules_file_path and harden invisible-char filter by @kdbrogan in https://github.com/awslabs/mcp/pull/4085
- fix(aws-transform-mcp-server): refuse downloads when write-base is fi… by @eswarjal in https://github.com/awslabs/mcp/pull/4270
- fix(cloudwatch-applicationsignals): validate enablement guide platform/language inputs by @wangzlei in https://github.com/awslabs/mcp/pull/4046
- fix(eks-mcp-server): handle null optional fields in get_k8s_events by @edobusy in https://github.com/awslabs/mcp/pull/4134
- fix(billing-cost-management-mcp-server): raise fastmcp floor to >=3.0.0 by @wangyuhere in https://github.com/awslabs/mcp/pull/4271
- fix(eks-mcp-server): support EKS CAs without AKI by @jstar0 in https://github.com/awslabs/mcp/pull/4121
- chore(aws-api-mcp-server): upgrade AWS CLI to v1.45.51 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4278
- chore: update IAM MCP codeowners by @arnewouters in https://github.com/awslabs/mcp/pull/4284
- chore(deps): update github-actions: bump the github-actions-version-updates group across 1 directory with 18 updates by @dependabot[bot] in https://github.com/awslabs/mcp/pull/4066
- chore(eks-mcp-server): update CODEOWNERS for eks-mcp-server by @srhsrhsrhsrh in https://github.com/awslabs/mcp/pull/4290
- chore(codeowners): remove vishaalmehrishi from the list of AWS IaC MC… by @vishaalmehrishi in https://github.com/awslabs/mcp/pull/4283
- fix(postgres-mcp-server): offload blocking boto3 credential calls in pool refresh by @aryanputta in https://github.com/awslabs/mcp/pull/3809
- refactor(aws-documentation-mcp-server): drop seo_abstract from search result context by @zjerath in https://github.com/awslabs/mcp/pull/4298
- fix(iam-mcp-server): partition-independent policy denylist and service-wildcard detection by @tildemit in https://github.com/awslabs/mcp/pull/4268
- chore(aws-api-mcp-server): upgrade AWS CLI to v1.45.53 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4301
- fix(aws-api-mcp-server): Security Policy Bypass via Startup Initialization Failure by @arnewouters in https://github.com/awslabs/mcp/pull/4315
- chore: release/2026.07.20260722140608 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4316
New Contributors
- @watilde made their first contribution in https://github.com/awslabs/mcp/pull/4106
- @S-gunasekhar made their first contribution in https://github.com/awslabs/mcp/pull/3518
- @eswarjal made their first contribution in https://github.com/awslabs/mcp/pull/4270
- @edobusy made their first contribution in https://github.com/awslabs/mcp/pull/4134
- @jstar0 made their first contribution in https://github.com/awslabs/mcp/pull/4121
- @aryanputta made their first contribution in https://github.com/awslabs/mcp/pull/3809
- @tildemit made their first contribution in https://github.com/awslabs/mcp/pull/4268
Full Changelog: https://github.com/awslabs/mcp/compare/2026.07.20260713210810...2026.07.20260722140608
Security Fixes
- openapi-mcp-server: block external $ref SSRF/LFI in spec parsing
- aws-api-mcp-server: fix Security Policy Bypass via Startup Initialization Failure
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]