Vulnerability Description
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-052-aws/
- https://github.com/agentic-community/mcp-gateway-registry/releases/tag/v1.0.13
- https://github.com/agentic-community/mcp-gateway-registry/security/advisories/GH
FAQ
What is CVE-2026-14471?
CVE-2026-14471 is a vulnerability with a CVSS score of 8.1 (HIGH). Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execut...
How severe is CVE-2026-14471?
CVE-2026-14471 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14471?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.