Skip to main content

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Bulletin ID: 2026-064-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/23/2026 11:30 AM PDT

Description:

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris" denial of service.

Impacted versions: aws-smithy-http-server <= 0.66.4

Resolution:

This issue has been addressed in aws-smithy-http-server version 0.66.5. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

There is no workaround besides upgrading to the patched version.

References:

Acknowledgement:

We would like to thank Lav Kumar Vishwakarma (independent security researcher) on this issue through the coordinated vulnerability disclosure process.
 

Please email aws-security@amazon.com with any security questions or concerns.