CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
Bulletin ID: 2026-061-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/21/2026 12:30 PM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-15957, where uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow a third party to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server.
Impacted versions: aws-sdk-rust crates < release-2026-06-0
Resolution:
This issue has been addressed in release-2026-06-02. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no workaround beyond updating to the patched versions.
References:
Please email aws-security@amazon.com with any security questions or concerns.