Server-Side Request Forgery in AWS HealthLake MCP Server by AWS
CVE-2026-15643

9.2CRITICAL

Key Information:

Vendor

Aws

Vendor
CVE Published:
14 July 2026

What is CVE-2026-15643?

The AWS HealthLake MCP Server, used for enabling AI assistants to interact with AWS HealthLake FHIR datastores, is vulnerable to a server-side request forgery due to improper validation in its pagination handling. Specifically, an attacker can exploit this vulnerability by crafting a malicious next_token parameter, which can result in the exfiltration of AWS temporary security credentials. The vulnerability exists in versions prior to 0.0.14 and allows authenticated users to redirect requests to malicious endpoints, posing serious security risks. To mitigate this vulnerability, it is crucial to upgrade to version 0.0.14 or later.

Affected Version(s)

awslabs.healthlake-mcp-server 0 < 0.0.14

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.