Junglewise Threat Intelligence

CVE-2026-15643: AWS HealthLake MCP Server SSRF in pagination handling

CVE-2026-15643 · Severity: high · CVSS 7.3 · Published 2026-07-14

Technologies: Amazon AWS. Vendors: Amazon, AWS.

Executive brief

AWS HealthLake MCP Server contains a Server-Side Request Forgery (SSRF) vulnerability in its pagination parameter handling. An attacker can exploit this to make the server perform unauthorized requests to internal or external systems, potentially accessing sensitive data or attacking systems within the internal network. This could allow an attacker to bypass security controls and access resources that should not be directly accessible.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the AWS HealthLake MCP Server, specifically in the pagination URL validation logic. The vulnerable component fails to properly validate or sanitize pagination URLs, allowing an attacker to inject arbitrary URLs that the server will fetch or process. The attack vector requires network access to the HealthLake MCP Server endpoint. An attacker can craft malicious pagination parameters to direct the server to access internal resources (via localhost, private IP ranges, or cloud metadata endpoints) or perform requests to arbitrary external systems. Successful exploitation could lead to information disclosure, access to sensitive configurations, or lateral movement within the network.

Affected products

  • AWS HealthLake MCP Server

Timeline

  • 2026-09-22: disclosed

References

Related threats