CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
Bulletin ID: 2026-067-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/30/2026 11:00 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-18140. Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server.
Impacted versions: aws-smithy-json <= 0.62.6
Resolution:
This issue has been addressed in aws-smithy-json version 0.62.7. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no workaround besides updating to the patched version.
References:
GHSA-8ffr-xgwf-xj56
CVE-2026-18140
Please email aws-security@amazon.com with any security questions or concerns.