To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild. | |
| Title | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers | |
| First Time appeared |
Aws
Aws aws-smithy-json |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:aws:aws-smithy-json:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-smithy-json |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-30T19:12:50.560Z
Reserved: 2026-07-28T18:30:40.451Z
Link: CVE-2026-18140
No data.
No data.
No data.
OpenCVE Enrichment
No data.