PT-2026-62047 · Amazon · Aws-Sdk-Rust+1

CVE-2026-15957

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aws-sdk-rust versions prior to release-2026-06-02 smithy-rs versions prior to release-2026-06-01
Description Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by the code generation framework can lead to a denial of service. A remote attacker can cause a process abort via stack exhaustion by sending a small request containing deeply nested data for a recursive model shape to a generated SDK or server.
Recommendations Upgrade aws-sdk-rust to release-2026-06-02 or later. Regenerate custom servers using smithy-rs release-2026-06-01 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15957
GHSA-4F2P-7J38-4XRG

Affected Products

Aws-Sdk-Rust
Smithy-Rs