CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris" denial of service.
Impacted versions: aws-smithy-http-server <= 0.66.4
Resolution:
This issue has been addressed in aws-smithy-http-server version 0.66.5. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no workaround besides upgrading to the patched version.
References:
Acknowledgement:
We would like to thank Lav Kumar Vishwakarma (independent security researcher) on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.