Amazon · Mcp Gateway & Registry · CVE-2026-14471
**Name of the Vulnerable Software and Affected Versions**
Amazon mcp-gateway-registry versions prior to 1.0.13
**Description**
The metrics-service retention policy management component fails to properly neutralize special elements. This allows an authenticated remote user to execute arbitrary SQL queries by providing a crafted `table name` value, which is then interpolated into SQL statements in an identifier position.
**Recommendations**
Upgrade to version 1.0.13 or later.