Skip to main content

CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers

Bulletin ID: 2026-067-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/30/2026 11:00 AM PDT

Description:

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-18140. Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server.

Impacted versions: aws-smithy-json <= 0.62.6

Resolution:

This issue has been addressed in aws-smithy-json version 0.62.7. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

There is no workaround besides updating to the patched version.

References:

GHSA-8ffr-xgwf-xj56
CVE-2026-18140

Please email aws-security@amazon.com with any security questions or concerns.