PT-2026-62047 · Amazon · Aws-Sdk-Rust+1
CVE-2026-15957
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
aws-sdk-rust versions prior to release-2026-06-02
smithy-rs versions prior to release-2026-06-01
Description
Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by the code generation framework can lead to a denial of service. A remote attacker can cause a process abort via stack exhaustion by sending a small request containing deeply nested data for a recursive model shape to a generated SDK or server.
Recommendations
Upgrade aws-sdk-rust to release-2026-06-02 or later.
Regenerate custom servers using smithy-rs release-2026-06-01 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Sdk-Rust
Smithy-Rs