To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild. | |
| Title | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers | |
| First Time appeared |
Aws
Aws aws-smithy-json |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:aws:aws-smithy-json:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-smithy-json |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-30T19:12:50.560Z
Reserved: 2026-07-28T18:30:40.451Z
Link: CVE-2026-18140
Updated: 2026-07-30T19:12:45.317Z
No data.
No data.
OpenCVE Enrichment
No data.