CVE-2026-18140High· 7.5▾ Twilightaws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists which allows uncontrolled recursion in the unknown-key skip path of the Amazon aws-smithy-json runtime crate in versions 0.62.6 and earlier.
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server.
Impacted versions: aws-smithy-json <= 0.62.6
This issue has been addressed in aws-smithy-json version 0.62.7. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
There are no workarounds besides updating to the patched version.
If you have any questions or comments about this advisory, AWS asks that you contact [AWS/Amazon] Security via their vulnerability reporting page or directly via email to [email protected]. Please do not create a public GitHub issue.
aws-smithy-json <= 0.62.6Upgrade to a patched release:
aws-smithy-json 0.62.7Connected by shared product, vendor, weakness, or advisory.
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2022-50407Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test
CVE-2026-53531MediumRaTeX is a KaTeX-compatible math rendering engine written in Rust
GHSA-q729-696q-g9pqHigh· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
GHSA-q8qp-67f9-wr3fMedium· 6.5SurrealDB vulnerable to Denial of Service due to nested types annotations
GHSA-jv2j-mqmw-xvv5Medium· 6.5SurrealDB: Denial of Service via deep operator chains